<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Custom Rule Report in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Custom-Rule-Report/m-p/124217#M75227</link>
    <description>&lt;P&gt;Depending on the rule that's being matched, it may not be possible to run a report.&lt;BR /&gt;The main reason being SmartEvent generally does not index connection logs from the firewall blade, only sessions (generally things that are tracked by a higher-level blade like App Control).&lt;BR /&gt;That said, I can think of a couple ways to do this:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Use SmartView to export the last million logs against the relevant rule into a CSV file, where you can import to Excel or similar.&lt;/LI&gt;
&lt;LI&gt;You can also get some rough statistics in SmartView, but you'd have to scroll through the various log entries to get them to load into memory so the stats can be shown.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2021-07-16 at 2.59.15 PM.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/12709iAA2E94E9DC860AB1/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screen Shot 2021-07-16 at 2.59.15 PM.png" alt="Screen Shot 2021-07-16 at 2.59.15 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
    <pubDate>Fri, 16 Jul 2021 22:01:31 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2021-07-16T22:01:31Z</dc:date>
    <item>
      <title>Custom Rule Report</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Custom-Rule-Report/m-p/123863#M75226</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; I have inherited a R80.40 system and I have a few rules that are allowing more than I would like. Now I know a few Services (Ports/Protocols) that are going through I want to remove, but going through the logs and trying to weed everything out is painful. I was wondering if I could write a report for a specific rule that would show the top number of Service's (Ports/Protocols) that were going through that rule? If this is possible then I could move things to more appropriate places or black them all together and trim the fat so to speak.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Scott&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jul 2021 21:16:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Custom-Rule-Report/m-p/123863#M75226</guid>
      <dc:creator>ScottG67</dc:creator>
      <dc:date>2021-07-14T21:16:12Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Rule Report</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Custom-Rule-Report/m-p/124217#M75227</link>
      <description>&lt;P&gt;Depending on the rule that's being matched, it may not be possible to run a report.&lt;BR /&gt;The main reason being SmartEvent generally does not index connection logs from the firewall blade, only sessions (generally things that are tracked by a higher-level blade like App Control).&lt;BR /&gt;That said, I can think of a couple ways to do this:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Use SmartView to export the last million logs against the relevant rule into a CSV file, where you can import to Excel or similar.&lt;/LI&gt;
&lt;LI&gt;You can also get some rough statistics in SmartView, but you'd have to scroll through the various log entries to get them to load into memory so the stats can be shown.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2021-07-16 at 2.59.15 PM.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/12709iAA2E94E9DC860AB1/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screen Shot 2021-07-16 at 2.59.15 PM.png" alt="Screen Shot 2021-07-16 at 2.59.15 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Fri, 16 Jul 2021 22:01:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Custom-Rule-Report/m-p/124217#M75227</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-07-16T22:01:31Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Rule Report</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Custom-Rule-Report/m-p/124709#M75228</link>
      <description>&lt;P&gt;Thanks a lot for the explanation. I will look into this and report back.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Jul 2021 18:03:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Custom-Rule-Report/m-p/124709#M75228</guid>
      <dc:creator>ScottG67</dc:creator>
      <dc:date>2021-07-22T18:03:34Z</dc:date>
    </item>
  </channel>
</rss>

