<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Log query R80.10 in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-query-R80-10/m-p/63606#M83880</link>
    <description>&lt;P&gt;Version: R80.10&lt;BR /&gt;Build: SmartConsole 991140013&lt;BR /&gt;&lt;BR /&gt;I would like to query a list of&amp;nbsp;&lt;STRONG&gt;unique&amp;nbsp;&lt;/STRONG&gt;IP addresses. So two (possible) queries might look like this (separated by a space, since the AND is implicit):&lt;BR /&gt;&lt;BR /&gt;Query 1:&lt;BR /&gt;&lt;BR /&gt;IP1 IP2 IP3&lt;BR /&gt;&lt;BR /&gt;Query 2:&lt;BR /&gt;&lt;BR /&gt;IP2 IP2 IP3 NOT action:drop&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 24 Sep 2019 22:23:01 GMT</pubDate>
    <dc:creator>resu</dc:creator>
    <dc:date>2019-09-24T22:23:01Z</dc:date>
    <item>
      <title>Log query R80.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-query-R80-10/m-p/63194#M83877</link>
      <description>&lt;P&gt;I would like to run a query (something like NOT action:drop) on a list of unique IP addresses. I've looked through documentation and tried IP's with a space between, with "AND" (no quote marks) between. Neither worked.&amp;nbsp;&lt;BR /&gt;Any advice is appreciated.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Sep 2019 19:48:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-query-R80-10/m-p/63194#M83877</guid>
      <dc:creator>resu</dc:creator>
      <dc:date>2019-09-19T19:48:35Z</dc:date>
    </item>
    <item>
      <title>Re: Log query R80.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-query-R80-10/m-p/63213#M83878</link>
      <description>&lt;P&gt;When you use queries with more than one criteria value, an AND is implied automatically, so there&amp;nbsp;is no need to add it. Enter OR or other boolean operators if needed.&lt;/P&gt;&lt;P&gt;&lt;A href="http://downloads.checkpoint.com/dc/download.htm?ID=65843" target="_blank"&gt;http://downloads.checkpoint.com/dc/download.htm?ID=65843&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Sep 2019 01:08:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-query-R80-10/m-p/63213#M83878</guid>
      <dc:creator>Gomboragchaa</dc:creator>
      <dc:date>2019-09-20T01:08:29Z</dc:date>
    </item>
    <item>
      <title>Re: Log query R80.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-query-R80-10/m-p/63341#M83879</link>
      <description>&lt;P&gt;Hi resu,&lt;/P&gt;
&lt;P&gt;Can you please share the exact queries that fail to find your desired results&amp;nbsp;and&amp;nbsp;exact R80.10 JHF-version?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 22 Sep 2019 09:21:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-query-R80-10/m-p/63341#M83879</guid>
      <dc:creator>Dror_Aharony</dc:creator>
      <dc:date>2019-09-22T09:21:22Z</dc:date>
    </item>
    <item>
      <title>Re: Log query R80.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-query-R80-10/m-p/63606#M83880</link>
      <description>&lt;P&gt;Version: R80.10&lt;BR /&gt;Build: SmartConsole 991140013&lt;BR /&gt;&lt;BR /&gt;I would like to query a list of&amp;nbsp;&lt;STRONG&gt;unique&amp;nbsp;&lt;/STRONG&gt;IP addresses. So two (possible) queries might look like this (separated by a space, since the AND is implicit):&lt;BR /&gt;&lt;BR /&gt;Query 1:&lt;BR /&gt;&lt;BR /&gt;IP1 IP2 IP3&lt;BR /&gt;&lt;BR /&gt;Query 2:&lt;BR /&gt;&lt;BR /&gt;IP2 IP2 IP3 NOT action:drop&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Sep 2019 22:23:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-query-R80-10/m-p/63606#M83880</guid>
      <dc:creator>resu</dc:creator>
      <dc:date>2019-09-24T22:23:01Z</dc:date>
    </item>
    <item>
      <title>Re: Log query R80.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-query-R80-10/m-p/63636#M83881</link>
      <description>&lt;P&gt;if both these queries fail (even without the NOT),&amp;nbsp;only free-text IPs, then it's already fixed in the latest JHF.&lt;/P&gt;
&lt;P&gt;for R80.10 only, you need to write either a src or dst. as a complete IP free-text wasn't supported.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also, I think what you're looking for is an &lt;STRONG&gt;OR&lt;/STRONG&gt;, not an AND here. (as you'll probably never have 3 unique IPs in the same log).&lt;/P&gt;
&lt;P&gt;example: (src:X OR dst:X) &lt;STRONG&gt;OR&lt;/STRONG&gt; (src:Y OR dst:Y)&lt;/P&gt;
&lt;P&gt;then you can add: &lt;STRONG&gt;AND action:Drop&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best to install the latest JHF anyway.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Sep 2019 08:40:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-query-R80-10/m-p/63636#M83881</guid>
      <dc:creator>Dror_Aharony</dc:creator>
      <dc:date>2019-09-25T08:40:14Z</dc:date>
    </item>
    <item>
      <title>Re: Log query R80.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-query-R80-10/m-p/78590#M83882</link>
      <description>&lt;P&gt;Apologies. I may have misunderstood how you define "log".&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Does "log" mean a single line item of traffic? I was thinking of that as an "entry" or "record" but am happy to be corrected.&lt;BR /&gt;&lt;BR /&gt;If "log" means a collection of rows of traffic events, then I would say that I see multiple IP's in a log all the time.&lt;BR /&gt;&lt;BR /&gt;I'm using R80.30&lt;/P&gt;</description>
      <pubDate>Tue, 17 Mar 2020 19:55:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-query-R80-10/m-p/78590#M83882</guid>
      <dc:creator>resu</dc:creator>
      <dc:date>2020-03-17T19:55:04Z</dc:date>
    </item>
    <item>
      <title>Re: Log query R80.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-query-R80-10/m-p/80181#M83883</link>
      <description>&lt;P&gt;Log = single line of traffic.&lt;/P&gt;
&lt;P&gt;Unique IP of either src/dst (usually).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;try &lt;STRONG&gt;OR &lt;/STRONG&gt;instead of AND (implicit AND) &amp;amp; let me know if this works out for you.&lt;/P&gt;
&lt;P&gt;src:(X OR Y OR Z) NOT action:Drop.&lt;/P&gt;
&lt;P&gt;or&lt;/P&gt;
&lt;P&gt;src:X OR src:Y OR src:Z NOT action:Drop.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Mar 2020 09:45:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-query-R80-10/m-p/80181#M83883</guid>
      <dc:creator>Dror_Aharony</dc:creator>
      <dc:date>2020-03-30T09:45:05Z</dc:date>
    </item>
    <item>
      <title>Re: Log query R80.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-query-R80-10/m-p/80202#M83884</link>
      <description>Apologies, didn't see other post. Thanks very much, this is it.</description>
      <pubDate>Mon, 30 Mar 2020 15:24:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-query-R80-10/m-p/80202#M83884</guid>
      <dc:creator>resu</dc:creator>
      <dc:date>2020-03-30T15:24:23Z</dc:date>
    </item>
  </channel>
</rss>

