<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SmartEvent Alert emails missing details in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SmartEvent-Alert-emails-missing-details/m-p/147313#M72191</link>
    <description>&lt;P&gt;Thanks for your suggestion.&amp;nbsp; I don't think this is relevant though as it isn't &lt;EM&gt;only&lt;/EM&gt; the username missing - it's all information&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 28 Apr 2022 10:12:25 GMT</pubDate>
    <dc:creator>biskit</dc:creator>
    <dc:date>2022-04-28T10:12:25Z</dc:date>
    <item>
      <title>SmartEvent Alert emails missing details</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SmartEvent-Alert-emails-missing-details/m-p/147170#M72189</link>
      <description>&lt;P&gt;I've enabled Anti-Bot email alerts in SmartEvent - all default settings, as follows:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SmartEvent.jpg" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/16203iEDAC04772333F010/image-size/large?v=v2&amp;amp;px=999" role="button" title="SmartEvent.jpg" alt="SmartEvent.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;The email alerts I get have very little detail in them.&amp;nbsp; They don't contain any source/destination/attack details, so the emails are zero use to me.&amp;nbsp; E.g:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Email1.jpg" style="width: 929px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/16204iF4647AC3A8AFDC40/image-size/large?v=v2&amp;amp;px=999" role="button" title="Email1.jpg" alt="Email1.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;However the corresponding log card for the issue contains all of the detail, as expected.&amp;nbsp; E.g:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="LogCard1.jpg" style="width: 979px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/16205i42441B371490E11B/image-size/large?v=v2&amp;amp;px=999" role="button" title="LogCard1.jpg" alt="LogCard1.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Does anyone know why the emails don't contain the same detail as the logs?&amp;nbsp; Or how to fix it to make the emails useful?&lt;/P&gt;</description>
      <pubDate>Wed, 27 Apr 2022 11:47:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SmartEvent-Alert-emails-missing-details/m-p/147170#M72189</guid>
      <dc:creator>biskit</dc:creator>
      <dc:date>2022-04-27T11:47:31Z</dc:date>
    </item>
    <item>
      <title>Re: SmartEvent Alert emails missing details</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SmartEvent-Alert-emails-missing-details/m-p/147224#M72190</link>
      <description>&lt;P&gt;Maybe you can try with this sk68020:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk68020" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk68020&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Apr 2022 16:57:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SmartEvent-Alert-emails-missing-details/m-p/147224#M72190</guid>
      <dc:creator>MikeB</dc:creator>
      <dc:date>2022-04-27T16:57:57Z</dc:date>
    </item>
    <item>
      <title>Re: SmartEvent Alert emails missing details</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SmartEvent-Alert-emails-missing-details/m-p/147313#M72191</link>
      <description>&lt;P&gt;Thanks for your suggestion.&amp;nbsp; I don't think this is relevant though as it isn't &lt;EM&gt;only&lt;/EM&gt; the username missing - it's all information&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Apr 2022 10:12:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SmartEvent-Alert-emails-missing-details/m-p/147313#M72191</guid>
      <dc:creator>biskit</dc:creator>
      <dc:date>2022-04-28T10:12:25Z</dc:date>
    </item>
    <item>
      <title>Re: SmartEvent Alert emails missing details</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SmartEvent-Alert-emails-missing-details/m-p/147323#M72192</link>
      <description>&lt;P&gt;I have a hunch for you to try...&lt;/P&gt;
&lt;P&gt;The email that you showed has "Log ID = 2000" and "Type = Correlated". That means that the automatic reaction was triggered on a correlated log, instead of on the original Anti-Bot log. The correlated log has only partial information, not the full info of the original log.&lt;/P&gt;
&lt;P&gt;Correlated logs aren't meant to be used for automatic reactions or further correlation (it can become recursive...). That's why in SmartEvent Event Policy there is a definition for "Global Exclusions" and the default is to exclude events with "Log ID = 2000" (see screenshot).&lt;/P&gt;
&lt;P&gt;Is it possible that you deleted this default filter or deactivated it?&lt;/P&gt;
&lt;DIV id="tinyMceEditor_20305f6065d2e4Tomer_Noy_0" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV id="tinyMceEditor_20305f6065d2e4Tomer_Noy_1" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="SmartEvent Global Exclusions.PNG" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/16237i91DB6E5961FE3354/image-size/large?v=v2&amp;amp;px=999" role="button" title="SmartEvent Global Exclusions.PNG" alt="SmartEvent Global Exclusions.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Apr 2022 12:34:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SmartEvent-Alert-emails-missing-details/m-p/147323#M72192</guid>
      <dc:creator>Tomer_Noy</dc:creator>
      <dc:date>2022-04-28T12:34:17Z</dc:date>
    </item>
    <item>
      <title>Re: SmartEvent Alert emails missing details</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SmartEvent-Alert-emails-missing-details/m-p/147331#M72193</link>
      <description>&lt;P&gt;Hi Tomer, unfortunately that Log ID 2000 rule is already there...&lt;/P&gt;</description>
      <pubDate>Thu, 28 Apr 2022 13:15:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SmartEvent-Alert-emails-missing-details/m-p/147331#M72193</guid>
      <dc:creator>biskit</dc:creator>
      <dc:date>2022-04-28T13:15:08Z</dc:date>
    </item>
    <item>
      <title>Re: SmartEvent Alert emails missing details</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SmartEvent-Alert-emails-missing-details/m-p/147373#M72194</link>
      <description>&lt;P&gt;I have same issue, the mail alert didn't show detail information, could not provide useful info.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Apr 2022 17:49:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SmartEvent-Alert-emails-missing-details/m-p/147373#M72194</guid>
      <dc:creator>Jarvis_Lin</dc:creator>
      <dc:date>2022-04-28T17:49:17Z</dc:date>
    </item>
    <item>
      <title>Re: SmartEvent Alert emails missing details</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SmartEvent-Alert-emails-missing-details/m-p/147532#M72195</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/26803"&gt;@biskit&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;Per the attached screenshot, the "Log Count" value is 1, which means that the correlated event was created by a &lt;U&gt;single&lt;/U&gt; update that doesn’t contain all relevant data as the unified log.&amp;nbsp;&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="shovalm_0-1651423208792.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/16310i0CB088082DA4D644/image-size/medium?v=v2&amp;amp;px=400" role="button" title="shovalm_0-1651423208792.png" alt="shovalm_0-1651423208792.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;My suggestion is to modify the advanced settings of "Bot Incident" event, so the event will kept opened for couple seconds before sending the mail, then we will have more data in the email.&lt;BR /&gt;For example :&lt;/P&gt;
&lt;DIV id="tinyMceEditor_2129b4528a2a71shovalm_1" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/16311i51532EB11F45405C/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;
&lt;P&gt;Let me know if it resolve the issue for you.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 01 May 2022 18:06:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SmartEvent-Alert-emails-missing-details/m-p/147532#M72195</guid>
      <dc:creator>shovalm</dc:creator>
      <dc:date>2022-05-01T18:06:39Z</dc:date>
    </item>
    <item>
      <title>Re: SmartEvent Alert emails missing details</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SmartEvent-Alert-emails-missing-details/m-p/147536#M72196</link>
      <description>&lt;P&gt;&lt;SPAN&gt;sk105300 describes a situation that might be worth checking further if you've not already.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 01 May 2022 23:43:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SmartEvent-Alert-emails-missing-details/m-p/147536#M72196</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-05-01T23:43:03Z</dc:date>
    </item>
    <item>
      <title>Re: SmartEvent Alert emails missing details</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SmartEvent-Alert-emails-missing-details/m-p/147558#M72197</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/39176"&gt;@shovalm&lt;/a&gt;&amp;nbsp;and&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/3630"&gt;@Chris_Atkinson&lt;/a&gt;,&amp;nbsp; thanks for your suggestions.&amp;nbsp; Neither seem to apply though.&amp;nbsp; See below.&amp;nbsp; The filter is already set on the custom alert...&amp;nbsp; And originally the Log Count was set to 39600 by default.&amp;nbsp; Last night I changed this to 10 as suggested above.&amp;nbsp; As you can see though, I'm still getting emails this morning with no detail in them, and see the times too - it's not like I'm getting a bunch of emails all at the same time, each containing a different bit of the information...&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Untitled2.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/16318iA57EC8C1504B916F/image-size/large?v=v2&amp;amp;px=999" role="button" title="Untitled2.png" alt="Untitled2.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Untitled.jpg" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/16319i4747EAC907D5AC5E/image-size/large?v=v2&amp;amp;px=999" role="button" title="Untitled.jpg" alt="Untitled.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 02 May 2022 08:30:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SmartEvent-Alert-emails-missing-details/m-p/147558#M72197</guid>
      <dc:creator>biskit</dc:creator>
      <dc:date>2022-05-02T08:30:16Z</dc:date>
    </item>
    <item>
      <title>Re: SmartEvent Alert emails missing details</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SmartEvent-Alert-emails-missing-details/m-p/147579#M72198</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/26803"&gt;@biskit&lt;/a&gt;&amp;nbsp;we want to investigate the issue further,&amp;nbsp;&lt;SPAN&gt;can you please contact Checkpoint support and open a service request for it ?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 02 May 2022 12:11:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SmartEvent-Alert-emails-missing-details/m-p/147579#M72198</guid>
      <dc:creator>shovalm</dc:creator>
      <dc:date>2022-05-02T12:11:36Z</dc:date>
    </item>
    <item>
      <title>Re: SmartEvent Alert emails missing details</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SmartEvent-Alert-emails-missing-details/m-p/147604#M72199</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/39176"&gt;@shovalm&lt;/a&gt;, yes of course.&amp;nbsp; I've already got an SR open and a remote session scheduled...&amp;nbsp; I often just post on CheckMates at the same time as I often get faster and more varied responses&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":beaming_face_with_smiling_eyes:"&gt;😁&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 02 May 2022 13:41:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SmartEvent-Alert-emails-missing-details/m-p/147604#M72199</guid>
      <dc:creator>biskit</dc:creator>
      <dc:date>2022-05-02T13:41:32Z</dc:date>
    </item>
    <item>
      <title>Re: SmartEvent Alert emails missing details</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SmartEvent-Alert-emails-missing-details/m-p/148619#M72200</link>
      <description>&lt;P&gt;After trying anything. I gave up set mail alert at SmartEvent.&lt;/P&gt;&lt;P&gt;I wrote a mail alert script and set track action to User Defined at rule and at global properties mail alert.&lt;/P&gt;&lt;P&gt;look like below, it has better visibility than original. I think RD can try to make original mail alert look more better.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="mailalert.png" style="width: 200px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/16545iC4218DE01B7CC767/image-size/small?v=v2&amp;amp;px=200" role="button" title="mailalert.png" alt="mailalert.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="mailalert1.png" style="width: 200px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/16546i2E77555478088069/image-size/small?v=v2&amp;amp;px=200" role="button" title="mailalert1.png" alt="mailalert1.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="mailalert2.png" style="width: 200px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/16547i0F740C255D60E08D/image-size/small?v=v2&amp;amp;px=200" role="button" title="mailalert2.png" alt="mailalert2.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 14 May 2022 15:34:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SmartEvent-Alert-emails-missing-details/m-p/148619#M72200</guid>
      <dc:creator>Jarvis_Lin</dc:creator>
      <dc:date>2022-05-14T15:34:15Z</dc:date>
    </item>
    <item>
      <title>Re: SmartEvent Alert emails missing details</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SmartEvent-Alert-emails-missing-details/m-p/149973#M72201</link>
      <description>&lt;P&gt;Any resolution to this issue?&amp;nbsp; I figured I'd post here and open a SR to see which gets a faster response.&amp;nbsp; &amp;nbsp;Just upgraded management R80.40 from Jumbo 139 to Jumbo 158 and the bot/virus auto-reaction emails are now all blank source/destination IP's immediately following.&amp;nbsp; Didn't update the gateways to jumbo 158 just yet.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Jun 2022 19:02:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SmartEvent-Alert-emails-missing-details/m-p/149973#M72201</guid>
      <dc:creator>George_Casper</dc:creator>
      <dc:date>2022-06-01T19:02:02Z</dc:date>
    </item>
    <item>
      <title>Re: SmartEvent Alert emails missing details</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SmartEvent-Alert-emails-missing-details/m-p/158080#M72202</link>
      <description>&lt;P&gt;Hi bisket, did you ever get a resolution on this from Support?&amp;nbsp; I'm having the same issue on R81.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Sep 2022 19:32:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SmartEvent-Alert-emails-missing-details/m-p/158080#M72202</guid>
      <dc:creator>Karen_Askelson</dc:creator>
      <dc:date>2022-09-26T19:32:35Z</dc:date>
    </item>
  </channel>
</rss>

