<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: smart event alerting of IPS prevent in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/smart-event-alerting-of-IPS-prevent/m-p/77031#M81408</link>
    <description>If you were to look at the log entry as it's shown with either fw log or CPLogFilePrint, it would look something like that.&lt;BR /&gt;What is sent depends on what information is in the log.</description>
    <pubDate>Tue, 03 Mar 2020 21:09:36 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2020-03-03T21:09:36Z</dc:date>
    <item>
      <title>smart event alerting of IPS prevent</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/smart-event-alerting-of-IPS-prevent/m-p/76608#M81400</link>
      <description>&lt;P&gt;I've been asked to set up an alert on traffic (even a single incident) that is &lt;STRONG&gt;prevented&lt;/STRONG&gt;&amp;nbsp;from an internal IP -&amp;gt; DMZ.&amp;nbsp; This seems easy, but is not possible with Smart Event.&amp;nbsp; It's rare that this traffic would be correlated, the &lt;STRONG&gt;PREVENT&lt;/STRONG&gt; just shows up as a single log - type NOT correlated.&amp;nbsp; THUS, the alert doesn't fire.&amp;nbsp; Does anyone know if there is a way?&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Creating Event Definitions (User Defined Events) - page 56 of the R77 smart event guide (I'm on R80.30, but this has the best documentation on user defined events.&amp;nbsp;&amp;nbsp;&lt;EM&gt;To create a user-defined event you must have knowledge of the method by which SmartEvent identifies events. This section starts with a high level overview of how logs are analyzed to conclude if an event occurs or occurred.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;When you create a user defined event, there is a COUNT LOGS tab and inside a radio button 'single log', this NEEDs to be updated to say single correlated log for accuracy.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Feb 2020 16:02:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/smart-event-alerting-of-IPS-prevent/m-p/76608#M81400</guid>
      <dc:creator>Daniel_Kavan</dc:creator>
      <dc:date>2020-02-27T16:02:35Z</dc:date>
    </item>
    <item>
      <title>Re: smart event alerting of IPS prevent</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/smart-event-alerting-of-IPS-prevent/m-p/76805#M81401</link>
      <description>&lt;P&gt;You're correct in that SmartEvent only works on correlated logs.&lt;BR /&gt;However, what you're asking can be done outside of SmartEvent.&lt;/P&gt;
&lt;P&gt;You can create an explicit rule for this server in your Threat Prevention policy and set the Track option to Mail and/or one of the User Alert options.&lt;BR /&gt;This will generate an email or run whatever script you specify on each log entry that is generated.&lt;BR /&gt;To configure Mail and/or User Alert options, refer to &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk25941" target="_self"&gt;sk25941&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2020-02-29 at 6.28.58 PM.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/4631iBD6C655458C9B32C/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screen Shot 2020-02-29 at 6.28.58 PM.png" alt="Screen Shot 2020-02-29 at 6.28.58 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 01 Mar 2020 02:34:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/smart-event-alerting-of-IPS-prevent/m-p/76805#M81401</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-03-01T02:34:51Z</dc:date>
    </item>
    <item>
      <title>Re: smart event alerting of IPS prevent</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/smart-event-alerting-of-IPS-prevent/m-p/76820#M81402</link>
      <description>&lt;P&gt;There is a better solution for your case. Create a custom rule for Threat Prevention policy layer, put there IPs and zones you need as source and destination. Set tracking for custom alert, et voila…&lt;/P&gt;</description>
      <pubDate>Sun, 01 Mar 2020 18:08:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/smart-event-alerting-of-IPS-prevent/m-p/76820#M81402</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2020-03-01T18:08:23Z</dc:date>
    </item>
    <item>
      <title>Re: smart event alerting of IPS prevent</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/smart-event-alerting-of-IPS-prevent/m-p/76871#M81403</link>
      <description>&lt;P&gt;Thanks for these responses!&lt;/P&gt;&lt;P&gt;However, the 'protected scope' doesn't seem to be specific enough.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a very specific case - I want alert on if it's from this IP address, x.x.x.1 &lt;STRONG&gt;AND&lt;/STRONG&gt; to this destination network y.y.y.0/24.&lt;/P&gt;&lt;P&gt;The protected scope is more of an 'either &lt;STRONG&gt;OR&lt;/STRONG&gt;' not an '&lt;STRONG&gt;AND&lt;/STRONG&gt;'. &amp;nbsp; IOW protected scope is if it's in/out to x.x.x.1 &lt;STRONG&gt;OR&lt;/STRONG&gt; in/out to y.y.y.0/24.&lt;/P&gt;&lt;P&gt;Maybe, the best we can do is a twice daily report on TP associated with&amp;nbsp; x.x.x.1.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Mar 2020 15:31:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/smart-event-alerting-of-IPS-prevent/m-p/76871#M81403</guid>
      <dc:creator>Daniel_Kavan</dc:creator>
      <dc:date>2020-03-02T15:31:22Z</dc:date>
    </item>
    <item>
      <title>Re: smart event alerting of IPS prevent</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/smart-event-alerting-of-IPS-prevent/m-p/76873#M81404</link>
      <description>&lt;P&gt;Right click on the rule headings and you can add source and destination columns.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="62FE9C5A-F49D-4399-9300-2596A397E79A.jpeg" style="width: 1959px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/4637i2D7035D8E91175AA/image-size/medium?v=v2&amp;amp;px=400" role="button" title="62FE9C5A-F49D-4399-9300-2596A397E79A.jpeg" alt="62FE9C5A-F49D-4399-9300-2596A397E79A.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Mon, 02 Mar 2020 15:34:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/smart-event-alerting-of-IPS-prevent/m-p/76873#M81404</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-03-02T15:34:28Z</dc:date>
    </item>
    <item>
      <title>Re: smart event alerting of IPS prevent</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/smart-event-alerting-of-IPS-prevent/m-p/76878#M81405</link>
      <description>&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;This will work, it looks like the limitation is you are limited to 3 custom alerts.&amp;nbsp; Alert no. 1, 2, &amp;amp; 3.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Mar 2020 16:21:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/smart-event-alerting-of-IPS-prevent/m-p/76878#M81405</guid>
      <dc:creator>Daniel_Kavan</dc:creator>
      <dc:date>2020-03-02T16:21:10Z</dc:date>
    </item>
    <item>
      <title>Re: smart event alerting of IPS prevent</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/smart-event-alerting-of-IPS-prevent/m-p/76879#M81406</link>
      <description>One called script can potentially do multiple things based on the input it receives.</description>
      <pubDate>Mon, 02 Mar 2020 16:23:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/smart-event-alerting-of-IPS-prevent/m-p/76879#M81406</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-03-02T16:23:40Z</dc:date>
    </item>
    <item>
      <title>Re: smart event alerting of IPS prevent</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/smart-event-alerting-of-IPS-prevent/m-p/76901#M81407</link>
      <description>&lt;P&gt;Is there a list somewhere that shows the stream sent when you call an alert?&amp;nbsp; What input does it receive?&amp;nbsp; I can write a script to use the data the script receives when an alert is generated, but what does that input/stream list look like?&lt;/P&gt;&lt;P&gt;I know with an email alert, a nice attachment that looks like the full record of the Prevent or Drop is sent.&lt;/P&gt;&lt;P&gt;However, with a script what is sent to the alert/script as input. &amp;nbsp; Yes, once you have that list, I can see how you can use it in a script to parse it and do different things.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Origin: $Origin&lt;/P&gt;&lt;P&gt;Blade: $Blade&lt;/P&gt;&lt;P&gt;Action: $Action&lt;/P&gt;&lt;P&gt;Attack Name: $Attack_Name&lt;/P&gt;&lt;P&gt;Attack Information: $Attack_Info&lt;/P&gt;&lt;P&gt;Source: $Source&lt;/P&gt;&lt;P&gt;Destination: $Destination&lt;/P&gt;&lt;P&gt;Severity: $Severity&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Mar 2020 18:32:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/smart-event-alerting-of-IPS-prevent/m-p/76901#M81407</guid>
      <dc:creator>Daniel_Kavan</dc:creator>
      <dc:date>2020-03-02T18:32:30Z</dc:date>
    </item>
    <item>
      <title>Re: smart event alerting of IPS prevent</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/smart-event-alerting-of-IPS-prevent/m-p/77031#M81408</link>
      <description>If you were to look at the log entry as it's shown with either fw log or CPLogFilePrint, it would look something like that.&lt;BR /&gt;What is sent depends on what information is in the log.</description>
      <pubDate>Tue, 03 Mar 2020 21:09:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/smart-event-alerting-of-IPS-prevent/m-p/77031#M81408</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-03-03T21:09:36Z</dc:date>
    </item>
    <item>
      <title>Re: smart event alerting of IPS prevent</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/smart-event-alerting-of-IPS-prevent/m-p/77467#M81409</link>
      <description>&lt;P&gt;TAC found more here:&amp;nbsp; &amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/R80.10/WebAdminGuides/EN/CP_R80.10_LoggingAndMonitoring_AdminGuide/html_frameset.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R80.10/WebAdminGuides/EN/CP_R80.10_LoggingAndMonitoring_AdminGuide/html_frameset.htm&lt;/A&gt;&lt;/P&gt;&lt;P&gt;This show how to pull the EVENT into the script.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Mar 2020 14:52:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/smart-event-alerting-of-IPS-prevent/m-p/77467#M81409</guid>
      <dc:creator>Daniel_Kavan</dc:creator>
      <dc:date>2020-03-06T14:52:02Z</dc:date>
    </item>
    <item>
      <title>Re: smart event alerting of IPS prevent</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/smart-event-alerting-of-IPS-prevent/m-p/96880#M81410</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;What scripting language/s can be used?&amp;nbsp; LLast time I tried python on Gaia &amp;amp; tried to wanted to add new modules/libraries, CP said I would invalidate the support if I added new libraries.&amp;nbsp; I think we talked about running a shell script that would call a python script on another server, but that would also involve passing the stream down to a different server.&lt;/P&gt;&lt;P&gt;Basically If attack_info = Zmap scan -&amp;gt; /dev/null, I want zmap secruity scans to be prevented but I don't want a case to fire off because of it.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Sep 2020 17:13:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/smart-event-alerting-of-IPS-prevent/m-p/96880#M81410</guid>
      <dc:creator>Daniel_Kavan</dc:creator>
      <dc:date>2020-09-16T17:13:06Z</dc:date>
    </item>
    <item>
      <title>Re: smart event alerting of IPS prevent</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/smart-event-alerting-of-IPS-prevent/m-p/96899#M81411</link>
      <description>&lt;P&gt;A bash script is where I would start as that doesn't require installing any other interpreters.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Sep 2020 01:27:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/smart-event-alerting-of-IPS-prevent/m-p/96899#M81411</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-09-17T01:27:52Z</dc:date>
    </item>
  </channel>
</rss>

