<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Log reporting in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-reporting/m-p/127311#M74832</link>
    <description>&lt;P&gt;There is good link here for that topic too:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk150452&amp;amp;partition=Advanced&amp;amp;product=SmartEvent" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk150452&amp;amp;partition=Advanced&amp;amp;product=SmartEvent&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 18 Aug 2021 09:56:09 GMT</pubDate>
    <dc:creator>dupacv</dc:creator>
    <dc:date>2021-08-18T09:56:09Z</dc:date>
    <item>
      <title>Log reporting</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-reporting/m-p/127273#M74829</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I'm new here with this subject but I can't find solution so I'm trying it here. I have R80.40 and my goal is to create the report where I can see communication of source IP addresses with hit counts and actions to specific destination IP on specific destination port. Let's say I just want to see simple list of sources communicating to some specific DNS server.&lt;/P&gt;&lt;P&gt;I was able to do something like that in reports but problem is that I can't see the data like in "Logs" page (many and many lines) but I only see something different - it looks like it somehow do some security report from blades but it ignores all accepted communication from firewall and filtering to firewall blade shows some "nonsense" (probably not nonsense - there is probably reason why it shows something like that - but from my point of view it looks like nonsense when I see drop from only one source but in Log window I can see drop from hundreds of sources in one hour range ... ). But I need that too (to see accepted communication too) so I can see that there is for example communication from 192.168.1.2 and a few other sources to some DNS like 10.10.10.10. So for example between 192.168.1.2 and DNS server the communication was accepted in X logs but for example between another IP it was dropped Y times etc.&lt;/P&gt;&lt;P&gt;Is something like that possible in reports (show some access statistic table with sorted data from "Logs" table)? I saw some materials like:&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/R80.40/WebAdminGuides/EN/CP_R80.40_LoggingAndMonitoring_AdminGuide/Front-Matter/Front-Matter-How-to-Search-in-this-Book.htm?tocpath=_____1" target="_blank"&gt;https://sc1.checkpoint.com/documents/R80.40/WebAdminGuides/EN/CP_R80.40_LoggingAndMonitoring_AdminGuide/Front-Matter/Front-Matter-How-to-Search-in-this-Book.htm?tocpath=_____1&lt;/A&gt;&amp;nbsp;but I couldn't find solution for my goal. So I just did some filter in "Logs" page and exported that query to MS Excel and did what I want in Excel. The result was what I needed but it would be much easier if it was possible in reports just to filter log to some destination IPs, port:53 and sort it by source with Log counts and action. So I can see for example 400 lines with hits to my query and not 1000+ of logs with zero informational value without some calculus. Is it possible to make something like that in report tool?&lt;/P&gt;&lt;P&gt;Thank you for advices,&lt;/P&gt;&lt;P&gt;V.&lt;/P&gt;</description>
      <pubDate>Tue, 17 Aug 2021 20:07:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-reporting/m-p/127273#M74829</guid>
      <dc:creator>dupacv</dc:creator>
      <dc:date>2021-08-17T20:07:28Z</dc:date>
    </item>
    <item>
      <title>Re: Log reporting</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-reporting/m-p/127279#M74830</link>
      <description>&lt;P&gt;Firewall connection logs are not indexed by default.&lt;BR /&gt;That can be addressed via:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk143853" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk143853&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Aug 2021 21:17:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-reporting/m-p/127279#M74830</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-08-17T21:17:34Z</dc:date>
    </item>
    <item>
      <title>Re: Log reporting</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-reporting/m-p/127290#M74831</link>
      <description>&lt;P&gt;That's it, thank you!&lt;/P&gt;</description>
      <pubDate>Wed, 18 Aug 2021 05:06:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-reporting/m-p/127290#M74831</guid>
      <dc:creator>dupacv</dc:creator>
      <dc:date>2021-08-18T05:06:36Z</dc:date>
    </item>
    <item>
      <title>Re: Log reporting</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-reporting/m-p/127311#M74832</link>
      <description>&lt;P&gt;There is good link here for that topic too:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk150452&amp;amp;partition=Advanced&amp;amp;product=SmartEvent" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk150452&amp;amp;partition=Advanced&amp;amp;product=SmartEvent&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Aug 2021 09:56:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-reporting/m-p/127311#M74832</guid>
      <dc:creator>dupacv</dc:creator>
      <dc:date>2021-08-18T09:56:09Z</dc:date>
    </item>
  </channel>
</rss>

