<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Custom Mail alert in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Custom-Mail-alert/m-p/63742#M83795</link>
    <description>&lt;P&gt;A UserDefined alert executed on the SMS in whatever scripting language your SMS supports should do the trick.&amp;nbsp; Your custom script can parse and format the original log data the way you want, then invoke sendmail to send the formatted output in an email.&amp;nbsp; UserDefined alerts are set up in the SmartConsole under Global Properties...Log &amp;amp; Alert...Alerts.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 26 Sep 2019 13:06:50 GMT</pubDate>
    <dc:creator>Timothy_Hall</dc:creator>
    <dc:date>2019-09-26T13:06:50Z</dc:date>
    <item>
      <title>Custom Mail alert</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Custom-Mail-alert/m-p/63719#M83793</link>
      <description>&lt;P&gt;Hi, we want to get mail alert :&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;HeaderDateHour: 25Sep2019 11:04:47;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ContentVersion: 5;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;HighLevelLogKey: 6192227919086323757;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Uuid: {0x5d8b1f9f,0x6,0xd2f190a,0xc0000001};&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;SequenceNum: 68;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Action: drop;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Origin: fw1;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;IfDir: &amp;gt;;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;InterfaceName: bond1.600;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Alert: mail;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;and etc.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;but we have:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;HeaderDateHour: 25Sep2019 11:04:47; ContentVersion: 5; HighLevelLogKey: 6192227919086323757; Uuid: {0x5d8b1f9f,0x6,0xd2f190a,0xc0000001}; SequenceNum: 68; Action: drop; Origin: fw1; IfDir: &amp;gt;; InterfaceName: bond1.600; Alert: mail; OriginSicName: CN=fw1,O=srv-fwmgt-01.kfim.int.qaps4b; OriginSicName: CN=fw1,O=srv-fwmgt-01.kfim.int.qaps4b; HighLevelLogKey: 6192227919086323757; inzone: Internal; outzone: External; service_id: https; src: ******; dst: **********; proto: tcp; xlatesrc: fw-cluster; xlatedst: ; NAT_rulenum: 39; NAT_addtnl_rulenum: 1; UserCheck_incident_uid: A35E45FE-7E0B-1761-BA71-151F0654E3EF; user: Efimov-t (Efimov-t)(+)********** (V.Efimov)(+); src_user_name: Efimov-t (Efimov-t)(+)*******(V.Efimov)(+); src_machine_name:&amp;nbsp;&lt;/SPAN&gt;&lt;A href="mailto:ws091@kfim.int" target="_blank"&gt;ws091@kfim.int&lt;/A&gt;&lt;SPAN&gt;; src_user_dn: CN=Efimov-t,OU=Admins,OU=Special Users,DC=kfim,DC=int(+)CN=V.Efimov,OU=Spb-users,OU=User Departments,DC=kfim,DC=int(+); snid: ; dst_user_name: ; dst_machine_name: ; dst_user_dn: ; UP_match_table: TAB E_START; ROW_START: 0; match_id: 178; layer_uuid: a26ede25-151d-4e2f-a863-ebea21a98bfd; layer_name: Network; rule_uid: 41195f98-14b7-4b3e-b582-726db64e9333; rule_name: Users_HTTP_HTTPS; action: 2; parent_rule: 0; ROW_END: 0; ROW_START: 1; match_id: 16777234; layer_uuid: 91658237-8cf4-45ab-8726-bad986646bb7; layer_name: Application; rule_uid: 894cc470-c30c-4d83-b12b-f66866da1219; rule_name: Teamviewer_Block; action: 0; parent_rule: 0; ROW_END: 1; UP_match_table: TABLE_END; context_num: 1; ProductName: VPN-1 &amp;amp; FireWall-1; svc: https; sport_svc: 30570; xlatedport_svc: ; xlatesport_svc: 37809; ProductFamily: Network;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;what we should use in&amp;nbsp;Run mail alert script ? thank you&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Sep 2019 08:23:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Custom-Mail-alert/m-p/63719#M83793</guid>
      <dc:creator>Ntsolution</dc:creator>
      <dc:date>2019-09-26T08:23:01Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Mail alert</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Custom-Mail-alert/m-p/63721#M83794</link>
      <description>So you already get a mail alert and you want the formatting to be more readable, right?</description>
      <pubDate>Thu, 26 Sep 2019 08:40:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Custom-Mail-alert/m-p/63721#M83794</guid>
      <dc:creator>Danny</dc:creator>
      <dc:date>2019-09-26T08:40:33Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Mail alert</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Custom-Mail-alert/m-p/63742#M83795</link>
      <description>&lt;P&gt;A UserDefined alert executed on the SMS in whatever scripting language your SMS supports should do the trick.&amp;nbsp; Your custom script can parse and format the original log data the way you want, then invoke sendmail to send the formatted output in an email.&amp;nbsp; UserDefined alerts are set up in the SmartConsole under Global Properties...Log &amp;amp; Alert...Alerts.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Sep 2019 13:06:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Custom-Mail-alert/m-p/63742#M83795</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2019-09-26T13:06:50Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Mail alert</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Custom-Mail-alert/m-p/63779#M83796</link>
      <description>&lt;P&gt;Yea, i want to get more informative mail, for example:&lt;BR /&gt;HeaderDateHour: 25Sep2019 11:04:47;&lt;BR /&gt;ContentVersion: 5;&lt;BR /&gt;HighLevelLogKey: 6192227919086323757;&lt;BR /&gt;Uuid: {0x5d8b1f9f,0x6,0xd2f190a,0xc0000001};&lt;BR /&gt;SequenceNum: 68;&lt;BR /&gt;Action: drop;&lt;BR /&gt;Origin: fw1;&lt;BR /&gt;IfDir: &amp;gt;;&lt;BR /&gt;InterfaceName: bond1.600;&lt;BR /&gt;Alert: mail;&lt;/P&gt;&lt;P&gt;I have scripts: i&lt;SPAN&gt;nternal_sendmail -s 'Alert Checkpoint' -t ,,,,,,,,,,,,, -f ,,,,,,,@tkbip.ru ,,,,,,,,,@tkbip.ru&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Now i geting:&lt;BR /&gt;HeaderDateHour: 25Sep2019 11:04:47; ContentVersion: 5; HighLevelLogKey: 6192227919086323757; Uuid: {0x5d8b1f9f,0x6,0xd2f190a,0xc0000001}; SequenceNum: 68; Action: drop; Origin: fw1; IfDir: &amp;gt;; InterfaceName: bond1.600; Alert: mail; OriginSicName: CN=fw1,O=srv-fwmgt-01.kfim.int.qaps4b; OriginSicName: CN=fw1,O=srv-fwmgt-01.kfim.int.qaps4b; HighLevelLogKey: 6192227919086323757; inzone: Internal; outzone: External; service_id: https; src: 10.26.10.8; dst: 17.248.150.112; proto: tcp; xlatesrc: fw-cluster; xlatedst: ; NAT_rulenum: 39; NAT_addtnl_rulenum: 1; UserCheck_incident_uid: A35E45FE-7E0B-1761-BA71-151F0654E3EF; user: Efimov-t (Efimov-t)(+)Валентин Ефимов (V.Efimov)(+); src_user_name: Efimov-t (Efimov-t)(+)Валентин Ефимов (V.Efimov)(+); src_machine_name: ws091@kfim.int; src_user_dn: CN=Efimov-t,OU=Admins,OU=Special Users,DC=kfim,DC=int(+)CN=V.Efimov,OU=Spb-users,OU=User Departments,DC=kfim,DC=int(+); snid: ; dst_user_name: ; dst_machine_name: ; dst_user_dn: ; UP_match_table: TAB E_START; ROW_START: 0; match_id: 178; layer_uuid: a26ede25-151d-4e2f-a863-ebea21a98bfd; layer_name: Network; rule_uid: 41195f98-14b7-4b3e-b582-726db64e9333; rule_name: Users_HTTP_HTTPS; action: 2; parent_rule: 0; ROW_END: 0; ROW_START: 1; match_id: 16777234; layer_uuid: 91658237-8cf4-45ab-8726-bad986646bb7; layer_name: Application; rule_uid: 894cc470-c30c-4d83-b12b-f66866da1219; rule_name: Teamviewer_Block; action: 0; parent_rule: 0; ROW_END: 1; UP_match_table: TABLE_END; context_num: 1; ProductName: VPN-1 &amp;amp; FireWall-1; svc: https; sport_svc: 30570; xlatedport_svc: ; xlatesport_svc: 37809; ProductFamily: Network;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Sep 2019 07:08:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Custom-Mail-alert/m-p/63779#M83796</guid>
      <dc:creator>Ntsolution</dc:creator>
      <dc:date>2019-09-27T07:08:47Z</dc:date>
    </item>
  </channel>
</rss>

