<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: search in log for &amp;quot;PenaltyBox&amp;quot; not possible in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/search-in-log-for-quot-PenaltyBox-quot-not-possible/m-p/119716#M75673</link>
    <description>&lt;P&gt;Not every log field is indexed is for performance reasons.&lt;BR /&gt;That does make certain logs…harder to find.&lt;/P&gt;</description>
    <pubDate>Fri, 28 May 2021 15:30:45 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2021-05-28T15:30:45Z</dc:date>
    <item>
      <title>search in log for "PenaltyBox" not possible</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/search-in-log-for-quot-PenaltyBox-quot-not-possible/m-p/119710#M75672</link>
      <description>&lt;P&gt;Hello CheckMates,&lt;/P&gt;
&lt;P&gt;it's not possible to search in logs for entries blocked by PenaltyBox-feature&amp;nbsp; (fwaccel dos pbox...)&lt;/P&gt;
&lt;P&gt;Search for "Penalty" or "DOS" brings no results. Looks like these fields are not indexed ?&lt;/P&gt;
&lt;P&gt;Why not? Every shown field should be searchable.&lt;/P&gt;
&lt;P&gt;Any way to find these logs without to know the source IP ?&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="2021-05-28 09_38_38_penaltyBox_drop.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/11875iA65EC5850E079111/image-size/large?v=v2&amp;amp;px=999" role="button" title="2021-05-28 09_38_38_penaltyBox_drop.png" alt="2021-05-28 09_38_38_penaltyBox_drop.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 28 May 2021 13:17:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/search-in-log-for-quot-PenaltyBox-quot-not-possible/m-p/119710#M75672</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2021-05-28T13:17:42Z</dc:date>
    </item>
    <item>
      <title>Re: search in log for "PenaltyBox" not possible</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/search-in-log-for-quot-PenaltyBox-quot-not-possible/m-p/119716#M75673</link>
      <description>&lt;P&gt;Not every log field is indexed is for performance reasons.&lt;BR /&gt;That does make certain logs…harder to find.&lt;/P&gt;</description>
      <pubDate>Fri, 28 May 2021 15:30:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/search-in-log-for-quot-PenaltyBox-quot-not-possible/m-p/119716#M75673</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-05-28T15:30:45Z</dc:date>
    </item>
    <item>
      <title>Re: search in log for "PenaltyBox" not possible</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/search-in-log-for-quot-PenaltyBox-quot-not-possible/m-p/119721#M75674</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1447"&gt;@Wolfgang&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Not all fields in SmartLog are displayed in the console. In &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk144192" target="_self"&gt;sk144192&lt;/A&gt;&amp;nbsp; there are more log fields described that you can use. &lt;BR /&gt;&lt;BR /&gt;Maybe the following fields can help:&lt;BR /&gt;- securexl_message&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 28 May 2021 15:49:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/search-in-log-for-quot-PenaltyBox-quot-not-possible/m-p/119721#M75674</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2021-05-28T15:49:13Z</dc:date>
    </item>
    <item>
      <title>Re: search in log for "PenaltyBox" not possible</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/search-in-log-for-quot-PenaltyBox-quot-not-possible/m-p/119731#M75675</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21670"&gt;@HeikoAnkenbrand&lt;/a&gt;&amp;nbsp; and &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;No chance at all. None of the shown fields "SecureXL Message", "comment" or "Feature Name" is available to a filter.&lt;/P&gt;
&lt;P&gt;Same in old Logviewer.&lt;/P&gt;
&lt;P&gt;I'm not happy that you had no chance to find an information if the PenaltyBox is detecting something &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 28 May 2021 19:30:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/search-in-log-for-quot-PenaltyBox-quot-not-possible/m-p/119731#M75675</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2021-05-28T19:30:02Z</dc:date>
    </item>
    <item>
      <title>Re: search in log for "PenaltyBox" not possible</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/search-in-log-for-quot-PenaltyBox-quot-not-possible/m-p/120125#M75676</link>
      <description>&lt;P&gt;small update….&lt;/P&gt;
&lt;P&gt;With R81 the comment field is searchable. Now you can search „penalty box“ and there are results shown&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":grinning_face:"&gt;😀&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Jun 2021 18:35:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/search-in-log-for-quot-PenaltyBox-quot-not-possible/m-p/120125#M75676</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2021-06-01T18:35:02Z</dc:date>
    </item>
    <item>
      <title>Re: search in log for "PenaltyBox" not possible</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/search-in-log-for-quot-PenaltyBox-quot-not-possible/m-p/120155#M75677</link>
      <description>&lt;P&gt;I suspect there were some "under the hood" changes in R81 given you have to reindex all the logs when you upgrade.&lt;BR /&gt;Also, an interesting tidbit in the R81.10 EA release notes:&amp;nbsp;The Solr functionality is replaced with a PostgreSQL database to improve the stability and performance of the Security Management Server.&lt;BR /&gt;Which means: more under the hood changes are coming &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Jun 2021 04:22:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/search-in-log-for-quot-PenaltyBox-quot-not-possible/m-p/120155#M75677</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-06-02T04:22:38Z</dc:date>
    </item>
    <item>
      <title>Re: search in log for "PenaltyBox" not possible</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/search-in-log-for-quot-PenaltyBox-quot-not-possible/m-p/120600#M75678</link>
      <description>&lt;P&gt;Hi Wolfgang,&lt;/P&gt;&lt;P&gt;we had the same issue with R80.x. Because there was no solution for that, i tested some filter combinations and found a workaround.&lt;/P&gt;&lt;P&gt;Using the following filter to display the needed infos in logs:&lt;/P&gt;&lt;P&gt;(type:"Alert") and not (src:"ips of your internal network" or dst:"your ips from external networks")&lt;/P&gt;&lt;P&gt;It may be necessery to select or edit the correct profile for displaying the field "Firewall Message" in the logging table.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Jun 2021 10:26:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/search-in-log-for-quot-PenaltyBox-quot-not-possible/m-p/120600#M75678</guid>
      <dc:creator>olliM</dc:creator>
      <dc:date>2021-06-08T10:26:36Z</dc:date>
    </item>
    <item>
      <title>Re: search in log for "PenaltyBox" not possible</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/search-in-log-for-quot-PenaltyBox-quot-not-possible/m-p/150241#M75679</link>
      <description>&lt;P&gt;you can try with "penalty box"&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jun 2022 14:15:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/search-in-log-for-quot-PenaltyBox-quot-not-possible/m-p/150241#M75679</guid>
      <dc:creator>CheckPointerXL</dc:creator>
      <dc:date>2022-06-06T14:15:45Z</dc:date>
    </item>
  </channel>
</rss>

