<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Is there a way to see recipient and sender forensic data in Content Awarness blade logs? in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Is-there-a-way-to-see-recipient-and-sender-forensic-data-in/m-p/20013#M46446</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I know in general we are looking to improve our MTA support.&lt;/P&gt;&lt;P&gt;There are some MTA features mentioned here:&amp;nbsp;&lt;A href="https://community.checkpoint.com/message/18347"&gt;Check Point R80.20 Production and Public EA&lt;/A&gt;‌&lt;/P&gt;&lt;P&gt;Question: if the MTA supported Content Awareness, would you use it?&lt;/P&gt;&lt;P&gt;Or do you just want Content Awareness (or some other blade) to log the SMTP details?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 30 Apr 2018 21:35:59 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2018-04-30T21:35:59Z</dc:date>
    <item>
      <title>Is there a way to see recipient and sender forensic data in Content Awarness blade logs?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Is-there-a-way-to-see-recipient-and-sender-forensic-data-in/m-p/20012#M46445</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've just enabled Content Awarness blade and it's a very useful blade to see what files are being transferred inbound and outbound in company e-mail system.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When I started to search and analyze the logs, I became aware that there is no forensic e-mail data like&amp;nbsp; most important sender,and recipient fields... Without sender and recipient information in an e-mail security log file it's useless, cause it's like a FW log without source and destination.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As a matter of course, I asked this feature to local CP Tukey support and they escalated my question to CP Global. The answer is below which never satisfies me:&lt;/P&gt;
&lt;BLOCKQUOTE class="jive_macro_quote jive-quote jive_text_macro"&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Hello [name redacted]&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Here you are our develepor replay for your Issue&amp;nbsp;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;-You will only see sender and received when the Email is destined to the Check Point MTA.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;-MTA supports TE. AV and Anti-Spam.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;-Content awareness will not work with MTA and the Emails are processed in streaming mode (smtp). Therefore the logs will not show sender and receiver details&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Regards,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Medhat Girgis – Technical Support Engineer&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As a customer I'm willing the to have forensic e-mail security related data fields in SmartLog and also willing to have e-mail related syntax (like receipt, sender, subject etc) for Threat Emulation, Threat Extraction,Anti-Spam &amp;amp; E-Mail Security, Content Awareness blades and features.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Evren Buyer&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;‌ ‌ ‌ ‌ threat extraction ‌&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jan 2025 13:31:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Is-there-a-way-to-see-recipient-and-sender-forensic-data-in/m-p/20012#M46445</guid>
      <dc:creator>Evren_Buyer</dc:creator>
      <dc:date>2025-01-23T13:31:31Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a way to see recipient and sender forensic data in Content Awarness blade logs?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Is-there-a-way-to-see-recipient-and-sender-forensic-data-in/m-p/20013#M46446</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I know in general we are looking to improve our MTA support.&lt;/P&gt;&lt;P&gt;There are some MTA features mentioned here:&amp;nbsp;&lt;A href="https://community.checkpoint.com/message/18347"&gt;Check Point R80.20 Production and Public EA&lt;/A&gt;‌&lt;/P&gt;&lt;P&gt;Question: if the MTA supported Content Awareness, would you use it?&lt;/P&gt;&lt;P&gt;Or do you just want Content Awareness (or some other blade) to log the SMTP details?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Apr 2018 21:35:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Is-there-a-way-to-see-recipient-and-sender-forensic-data-in/m-p/20013#M46446</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-04-30T21:35:59Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a way to see recipient and sender forensic data in Content Awarness blade logs?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Is-there-a-way-to-see-recipient-and-sender-forensic-data-in/m-p/20014#M46447</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Dameon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My answer is gonna be ABSOLUTELY YES I will use it...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;May I be a volunteer for the Production and Public EA? How am I supposed to do that?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cause like Small business companies one of which I currently work for, they never like to pay so much for Security products, CP has great solutions;&amp;nbsp; I know there are many different security MTAs etc. but CP did well to collect them under one product with different blades. I also use different products like&amp;nbsp; Trend Micros IMSVA solution as a second Security Layer in my mail system, which can be supported with anti-ransomware products...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And also; positioning the CP in the middle of a star-topology like in my environment is the BEST...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;I think I love my CP&lt;/STRONG&gt; and that's why requesting, demanding more from it...! &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Benefits of CP that attracts me to use:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Correlated Rule base also correlated logs and management&lt;/P&gt;&lt;P&gt;2) Different layers different security solutions (Mail, application, FW, VPN, IPS etc)&lt;/P&gt;&lt;P&gt;3) Easy to coordinate with other products&lt;/P&gt;&lt;P&gt;4) And the MOST IMPORTANT---&amp;gt; All it's blades work &lt;STRONG&gt;trustfully&lt;/STRONG&gt;, fast, constant and stable...&lt;/P&gt;&lt;P&gt;5) Great forensic features in one hand&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/65236_pastedImage_3.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Evren Buyer&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 May 2018 06:21:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Is-there-a-way-to-see-recipient-and-sender-forensic-data-in/m-p/20014#M46447</guid>
      <dc:creator>Evren_Buyer</dc:creator>
      <dc:date>2018-05-02T06:21:43Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a way to see recipient and sender forensic data in Content Awarness blade logs?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Is-there-a-way-to-see-recipient-and-sender-forensic-data-in/m-p/20015#M46448</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The request to the EA went to the right place. &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 May 2018 17:30:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Is-there-a-way-to-see-recipient-and-sender-forensic-data-in/m-p/20015#M46448</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-05-02T17:30:31Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a way to see recipient and sender forensic data in Content Awarness blade logs?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Is-there-a-way-to-see-recipient-and-sender-forensic-data-in/m-p/20016#M46449</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;But still there is neither an answer nor reply from @EA_support &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 May 2018 07:45:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Is-there-a-way-to-see-recipient-and-sender-forensic-data-in/m-p/20016#M46449</guid>
      <dc:creator>Evren_Buyer</dc:creator>
      <dc:date>2018-05-03T07:45:34Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a way to see recipient and sender forensic data in Content Awarness blade logs?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Is-there-a-way-to-see-recipient-and-sender-forensic-data-in/m-p/130138#M46450</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/24229"&gt;@Evren_Buyer&lt;/a&gt;&amp;nbsp;r Did you have the possibility to try Content Awarness on MTA?&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp; there are some news in EA about this&amp;nbsp;functionality?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 24 Sep 2021 08:49:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Is-there-a-way-to-see-recipient-and-sender-forensic-data-in/m-p/130138#M46450</guid>
      <dc:creator>Bubba_95</dc:creator>
      <dc:date>2021-09-24T08:49:08Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a way to see recipient and sender forensic data in Content Awarness blade logs?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Is-there-a-way-to-see-recipient-and-sender-forensic-data-in/m-p/130225#M46451</link>
      <description>&lt;P&gt;As far as I know, Content Awareness is still not supported in MTA for the reasons mentioned above.&lt;BR /&gt;The EA features related to MTA above were released as part of R80.20 and should be available in later releases.&lt;BR /&gt;R80.30 and R80.40 also added additional MTA functionality, mostly Threat Prevention related.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Sep 2021 20:10:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Is-there-a-way-to-see-recipient-and-sender-forensic-data-in/m-p/130225#M46451</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-09-24T20:10:01Z</dc:date>
    </item>
  </channel>
</rss>

