<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IOC feeds: how to monitor and escalate issues? How to get alerts from ioc_feeder.elg to Service in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-feeds-how-to-monitor-and-escalate-issues-How-to-get-alerts/m-p/204387#M38540</link>
    <description>&lt;P&gt;If anyone is interested, i tested it in the lab. When detected, the lines with errors are ignored, and the rest of the feed is applied. Single error does not stop the fewst of the IOC file to be processed.&lt;/P&gt;&lt;P&gt;Errors are stored in *_custom.csv.err file on the gateways.&lt;/P&gt;&lt;P&gt;Even so, the details about the updates of the feed files are only available in ioc_feeder.elg log file on the Gateway, the most important is forwarded to SmartConsole fw.log file.&lt;/P&gt;&lt;P&gt;Smart Console events:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Picture1.png" style="width: 643px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/24278iEE4E86A1791E8627/image-size/large?v=v2&amp;amp;px=999" role="button" title="Picture1.png" alt="Picture1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Picture2.png" style="width: 643px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/24280iA07373E83BF2948D/image-size/large?v=v2&amp;amp;px=999" role="button" title="Picture2.png" alt="Picture2.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 28 Jan 2024 23:08:40 GMT</pubDate>
    <dc:creator>Sergej_Gurenko</dc:creator>
    <dc:date>2024-01-28T23:08:40Z</dc:date>
    <item>
      <title>IOC feeds: how to monitor and escalate issues? How to get alerts from ioc_feeder.elg to Service Desk</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-feeds-how-to-monitor-and-escalate-issues-How-to-get-alerts/m-p/204095#M38495</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I read several posts &lt;A href="https://community.checkpoint.com/t5/Security-Gateways/What-is-the-maximum-IOC-feed-range/td-p/173888" target="_self"&gt;What is the maximum IOC feed range?&lt;/A&gt; and &lt;A href="https://community.checkpoint.com/t5/Threat-Prevention/IOC-Feeds-does-not-work-properly/td-p/183938" target="_self"&gt;IOC Feeds does not work properly&lt;/A&gt;, describing potential issues with IOC feeds on older Check Point software. It is looks like all IOC feed suscess and failure erros are stored in ioc_feeder.elg&lt;/P&gt;&lt;P&gt;There are two scenarios i'm seeking assistance with:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Alerting traditional NOC if the feature is not working or is degraded. And further escalation via the ticket.&lt;/LI&gt;&lt;LI&gt;Alerting MDR analysts that the IOC feed is successfully imported and processed by the gateways. The analysts could modify and update IOC files by hand or using semi-automated playbooks and security tools.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;Can you please suggest on reliable option for getting the significant errors from ioc_feeder.elg to (Service Desk) tools.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;We can use scheduled SNMP polls, email integration or other old school methods.For example less preferred syslog alerts and SNMP-traps (as less reliable). We have not tried Skyline (OpenTelemetry prometheus grafana) yet and do not integrate with Infinity Portal for co-management. I read that *.ELG is a plain text file.&lt;/P&gt;&lt;P&gt;Regards, Serg&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jan 2024 19:49:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-feeds-how-to-monitor-and-escalate-issues-How-to-get-alerts/m-p/204095#M38495</guid>
      <dc:creator>Sergej_Gurenko</dc:creator>
      <dc:date>2024-01-24T19:49:47Z</dc:date>
    </item>
    <item>
      <title>Re: IOC feeds: how to monitor and escalate issues? How to get alerts from ioc_feeder.elg to Service</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-feeds-how-to-monitor-and-escalate-issues-How-to-get-alerts/m-p/204138#M38506</link>
      <description>&lt;P&gt;Hey,&lt;/P&gt;
&lt;P&gt;All our firewall logs are sent to an elastic instance with the log exporter. From here we have set up alerts on various logs. So when IOC stops working the firewall logs it, and we sent a webhook from elastic to our ITSM with relevant info.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Furthermore we have a query every X minute from a tooling server, that queries an item agreed to be in the feed. The query should be stopped. If it is not, we sent an alert to our ITSM system.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;/Henrik&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jan 2024 09:42:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-feeds-how-to-monitor-and-escalate-issues-How-to-get-alerts/m-p/204138#M38506</guid>
      <dc:creator>Henrik_Noerr1</dc:creator>
      <dc:date>2024-01-25T09:42:28Z</dc:date>
    </item>
    <item>
      <title>Re: IOC feeds: how to monitor and escalate issues? How to get alerts from ioc_feeder.elg to Service</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-feeds-how-to-monitor-and-escalate-issues-How-to-get-alerts/m-p/204149#M38508</link>
      <description>&lt;P&gt;I think it is an excellent hint to pre-provision a bunch of test remote destinations and hand over the details to the analysts. Rather than testing if&amp;nbsp; (potentially dangerous) malicious URL is blocked, the analysts can test the harmless test URLs.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jan 2024 12:11:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-feeds-how-to-monitor-and-escalate-issues-How-to-get-alerts/m-p/204149#M38508</guid>
      <dc:creator>Sergej_Gurenko</dc:creator>
      <dc:date>2024-01-25T12:11:47Z</dc:date>
    </item>
    <item>
      <title>Re: IOC feeds: how to monitor and escalate issues? How to get alerts from ioc_feeder.elg to Service</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-feeds-how-to-monitor-and-escalate-issues-How-to-get-alerts/m-p/204247#M38525</link>
      <description>&lt;P&gt;Add-on question: Does anyone know if a single error in the feed file blocks the update/refresh or if lines with the errors are ignored while the incorrect lines are pushed? The documentation does not provide a clear answer. Especially the "&lt;A href="https://support.checkpoint.com/results/sk/sk165932" target="_self"&gt;sk165932&lt;/A&gt; &lt;EM&gt;"IOC_FAILED_WHILE_PARSING" error message when the Custom Intelligence Feeds automatic process fails after editing the source file&lt;/EM&gt;" gives me the impression this is a bug.&lt;/P&gt;&lt;P&gt;From the documentation:&lt;/P&gt;&lt;P&gt;"IOC_FAILED_WHILE_PARSING" error message when Custom Intelligence Feeds automatic process fails after editing source file.&lt;BR /&gt;When adding an IP address, or domain, to the list, the system does not block the new address (still blocks the existing entries), and shows a parsing error: "IOC_FAILED_WHILE_PARSING"&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jan 2024 13:53:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-feeds-how-to-monitor-and-escalate-issues-How-to-get-alerts/m-p/204247#M38525</guid>
      <dc:creator>Sergej_Gurenko</dc:creator>
      <dc:date>2024-01-26T13:53:19Z</dc:date>
    </item>
    <item>
      <title>Re: IOC feeds: how to monitor and escalate issues? How to get alerts from ioc_feeder.elg to Service</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-feeds-how-to-monitor-and-escalate-issues-How-to-get-alerts/m-p/204387#M38540</link>
      <description>&lt;P&gt;If anyone is interested, i tested it in the lab. When detected, the lines with errors are ignored, and the rest of the feed is applied. Single error does not stop the fewst of the IOC file to be processed.&lt;/P&gt;&lt;P&gt;Errors are stored in *_custom.csv.err file on the gateways.&lt;/P&gt;&lt;P&gt;Even so, the details about the updates of the feed files are only available in ioc_feeder.elg log file on the Gateway, the most important is forwarded to SmartConsole fw.log file.&lt;/P&gt;&lt;P&gt;Smart Console events:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Picture1.png" style="width: 643px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/24278iEE4E86A1791E8627/image-size/large?v=v2&amp;amp;px=999" role="button" title="Picture1.png" alt="Picture1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Picture2.png" style="width: 643px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/24280iA07373E83BF2948D/image-size/large?v=v2&amp;amp;px=999" role="button" title="Picture2.png" alt="Picture2.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 28 Jan 2024 23:08:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-feeds-how-to-monitor-and-escalate-issues-How-to-get-alerts/m-p/204387#M38540</guid>
      <dc:creator>Sergej_Gurenko</dc:creator>
      <dc:date>2024-01-28T23:08:40Z</dc:date>
    </item>
    <item>
      <title>Re: IOC feeds: how to monitor and escalate issues? How to get alerts from ioc_feeder.elg to Service</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-feeds-how-to-monitor-and-escalate-issues-How-to-get-alerts/m-p/209301#M39647</link>
      <description>&lt;P&gt;Hello Experts, does anyone know if one can generate alerts from _specific_ messages in the SmartConsole fw.log file?&lt;/P&gt;&lt;P&gt;Thinking about handling IOC errors by firing Emails or SNMP traps to the monitoring platform.&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="alerts.jpg" style="width: 570px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/24961i036A3569A9684D92/image-size/large?v=v2&amp;amp;px=999" role="button" title="alerts.jpg" alt="alerts.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Mar 2024 15:27:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-feeds-how-to-monitor-and-escalate-issues-How-to-get-alerts/m-p/209301#M39647</guid>
      <dc:creator>Sergej_Gurenko</dc:creator>
      <dc:date>2024-03-20T15:27:05Z</dc:date>
    </item>
    <item>
      <title>Re: IOC feeds: how to monitor and escalate issues? How to get alerts from ioc_feeder.elg to Service</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-feeds-how-to-monitor-and-escalate-issues-How-to-get-alerts/m-p/209308#M39651</link>
      <description>&lt;P&gt;The filtering would have to occur in a script, sending mail or snmp trap only when specific messages are encountered.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Mar 2024 19:14:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-feeds-how-to-monitor-and-escalate-issues-How-to-get-alerts/m-p/209308#M39651</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-03-20T19:14:51Z</dc:date>
    </item>
  </channel>
</rss>

