<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SmartLog TLS filter in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SmartLog-TLS-filter/m-p/94916#M78797</link>
    <description>&lt;P&gt;It seems like searching for service:TLS1.0 would show you only TLSv1.0 logs.&lt;BR /&gt;Is that not the case?&lt;/P&gt;</description>
    <pubDate>Sat, 22 Aug 2020 05:50:12 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2020-08-22T05:50:12Z</dc:date>
    <item>
      <title>SmartLog TLS filter</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SmartLog-TLS-filter/m-p/94712#M78796</link>
      <description>&lt;P&gt;Hi guys&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope someone can help. I'm looking to setup a filter on SmartLog that shows me all TLS 1.0 traffic but not TLS 1.2 traffic.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Is this filter correct?&lt;/P&gt;
&lt;P&gt;Service:tls1.0 OR NOT Service:tls1.2&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I tried AND instead of OR but that didn't work. When try just one or the other, the results seem to be same.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Many thanks&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jun 2021 21:00:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SmartLog-TLS-filter/m-p/94712#M78796</guid>
      <dc:creator>ziggurat</dc:creator>
      <dc:date>2021-06-22T21:00:01Z</dc:date>
    </item>
    <item>
      <title>Re: SmartLog TLS filter</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SmartLog-TLS-filter/m-p/94916#M78797</link>
      <description>&lt;P&gt;It seems like searching for service:TLS1.0 would show you only TLSv1.0 logs.&lt;BR /&gt;Is that not the case?&lt;/P&gt;</description>
      <pubDate>Sat, 22 Aug 2020 05:50:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SmartLog-TLS-filter/m-p/94916#M78797</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-08-22T05:50:12Z</dc:date>
    </item>
    <item>
      <title>Re: SmartLog TLS filter</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SmartLog-TLS-filter/m-p/94946#M78798</link>
      <description>&lt;P&gt;That's what I expected too, but when applied filter "&lt;SPAN&gt;Service:tls1.0" the log seemed to show the same traffic as filter "Service:tls1.2" - I began to wonder whether "Service:tls1.0" will show all traffic passing on 1.0 upwards.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I could be totally wrong but output seems the same with either filter. It's a head scratcher...&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 22 Aug 2020 20:30:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SmartLog-TLS-filter/m-p/94946#M78798</guid>
      <dc:creator>ziggurat</dc:creator>
      <dc:date>2020-08-22T20:30:10Z</dc:date>
    </item>
    <item>
      <title>Re: SmartLog TLS filter</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SmartLog-TLS-filter/m-p/94977#M78799</link>
      <description>&lt;P&gt;Maybe&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/9799"&gt;@Dan_Zada&lt;/a&gt;&amp;nbsp;or someone on his team knows, but this may not be supported.&lt;/P&gt;</description>
      <pubDate>Mon, 24 Aug 2020 02:49:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SmartLog-TLS-filter/m-p/94977#M78799</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-08-24T02:49:35Z</dc:date>
    </item>
    <item>
      <title>Re: SmartLog TLS filter</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SmartLog-TLS-filter/m-p/94997#M78800</link>
      <description>&lt;P&gt;Many thanks, I'll continue fiddling around with the filter. Who knows, maybe I'll stumble across the solution &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Aug 2020 07:07:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SmartLog-TLS-filter/m-p/94997#M78800</guid>
      <dc:creator>ziggurat</dc:creator>
      <dc:date>2020-08-24T07:07:02Z</dc:date>
    </item>
    <item>
      <title>Re: SmartLog TLS filter</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SmartLog-TLS-filter/m-p/114919#M78801</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;BR /&gt;Did you find any solution to filter TLS version on SmartLog?&lt;BR /&gt;thanks&lt;/P&gt;</description>
      <pubDate>Tue, 30 Mar 2021 08:09:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SmartLog-TLS-filter/m-p/114919#M78801</guid>
      <dc:creator>Mufaaa</dc:creator>
      <dc:date>2021-03-30T08:09:14Z</dc:date>
    </item>
  </channel>
</rss>

