<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Smart Event not showing Accepted Log in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-Event-not-showing-Accepted-Log/m-p/112412#M85986</link>
    <description>&lt;P&gt;What are you hoping to get out of those logs in particular?&lt;BR /&gt;Yes, the only way they'd get processed by SmartEvent is if that option is enabled.&lt;/P&gt;</description>
    <pubDate>Wed, 03 Mar 2021 22:12:22 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2021-03-03T22:12:22Z</dc:date>
    <item>
      <title>Smart Event not showing Accepted Log</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-Event-not-showing-Accepted-Log/m-p/53489#M85976</link>
      <description>&lt;P&gt;Smart Event not showing Accepted and the Clean up rule is ANY ANY ALLOW.&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the Event when i select the policy package in the filter, the ACCEPT logs shows 0. I changed the Log&amp;nbsp; to Detailed and Extended and after the Accept log was available but when expanding the logs again it shows only DETECT logs.&lt;/P&gt;&lt;P&gt;Please any one help on this issue.&lt;/P&gt;</description>
      <pubDate>Wed, 15 May 2019 08:37:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-Event-not-showing-Accepted-Log/m-p/53489#M85976</guid>
      <dc:creator>sajin</dc:creator>
      <dc:date>2019-05-15T08:37:44Z</dc:date>
    </item>
    <item>
      <title>Re: Smart Event not showing Accepted Log</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-Event-not-showing-Accepted-Log/m-p/53733#M85977</link>
      <description>Generally firewall logs are NOT correlated by SmartEvent by default.&lt;BR /&gt;They must be enabled in the Event Policy.</description>
      <pubDate>Fri, 17 May 2019 20:27:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-Event-not-showing-Accepted-Log/m-p/53733#M85977</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-05-17T20:27:45Z</dc:date>
    </item>
    <item>
      <title>Re: Smart Event not showing Accepted Log</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-Event-not-showing-Accepted-Log/m-p/53734#M85978</link>
      <description>&lt;P&gt;Is the above solution works for Rule Name and Rule Number Filter as am not able to filter with these two option.&lt;/P&gt;</description>
      <pubDate>Fri, 17 May 2019 20:32:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-Event-not-showing-Accepted-Log/m-p/53734#M85978</guid>
      <dc:creator>sajin</dc:creator>
      <dc:date>2019-05-17T20:32:38Z</dc:date>
    </item>
    <item>
      <title>Re: Smart Event not showing Accepted Log</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-Event-not-showing-Accepted-Log/m-p/53931#M85979</link>
      <description>&lt;P&gt;You need to ensure Firewall Sessions are correlated (they are not by default).&lt;BR /&gt;Click on Logs and Monitor &amp;gt; New Tab &amp;gt; SmartEvent Settings and Policy and enable Firewall Sessions as shown.&lt;BR /&gt;Push the Event Policy afterwords.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.PNG" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/1259iA8A95B7F4D3B5150/image-size/large?v=v2&amp;amp;px=999" role="button" title="Capture.PNG" alt="Capture.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 20 May 2019 19:13:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-Event-not-showing-Accepted-Log/m-p/53931#M85979</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-05-20T19:13:29Z</dc:date>
    </item>
    <item>
      <title>Re: Smart Event not showing Accepted Log</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-Event-not-showing-Accepted-Log/m-p/53944#M85980</link>
      <description>SE does not correlate standard fw logs by default.</description>
      <pubDate>Mon, 20 May 2019 23:20:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-Event-not-showing-Accepted-Log/m-p/53944#M85980</guid>
      <dc:creator>tpoole_global</dc:creator>
      <dc:date>2019-05-20T23:20:08Z</dc:date>
    </item>
    <item>
      <title>Re: Smart Event not showing Accepted Log</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-Event-not-showing-Accepted-Log/m-p/67561#M85981</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I did it as per screenshot, however I don't see any events from firewall blade.&amp;nbsp; Am I missing something more?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Nov 2019 15:46:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-Event-not-showing-Accepted-Log/m-p/67561#M85981</guid>
      <dc:creator>abihsot__</dc:creator>
      <dc:date>2019-11-15T15:46:23Z</dc:date>
    </item>
    <item>
      <title>Re: Smart Event not showing Accepted Log</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-Event-not-showing-Accepted-Log/m-p/67602#M85982</link>
      <description>What is it that you're actually trying to get from SmartEvent related to these logs?</description>
      <pubDate>Fri, 15 Nov 2019 19:47:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-Event-not-showing-Accepted-Log/m-p/67602#M85982</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-11-15T19:47:22Z</dc:date>
    </item>
    <item>
      <title>Re: Smart Event not showing Accepted Log</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-Event-not-showing-Accepted-Log/m-p/67654#M85983</link>
      <description>&lt;P&gt;What Phoneboy suggested is the older but possible option to correlate FW logs into Correlated Events that the SME will show (should work).&lt;/P&gt;
&lt;P&gt;the better R80.10 &amp;amp; above alternative option is to generate a 'Session' log from your FW Rulebase policy, as&amp;nbsp;All Session logs are indexed &amp;amp; shown by the SME.&lt;/P&gt;
&lt;P&gt;using this method, you can decide which rules specifically to log into Session logs to also get indexed &amp;amp; shown by the SME.&lt;/P&gt;
&lt;P&gt;How-To: Relevant rule &amp;gt; Track &amp;gt; R-Click &amp;gt; More &amp;gt; Activate log 'per Session'.&lt;/P&gt;
&lt;P&gt;I'd advise to disable the 1st suggested option of activating Consolidated FW Sessions, if you decide on the 2nd Rulebase 'per Session' option, as it only puts an unnecessary load on your SME server to consolidate All FW logs into correlated events.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 17 Nov 2019 12:34:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-Event-not-showing-Accepted-Log/m-p/67654#M85983</guid>
      <dc:creator>Dror_Aharony</dc:creator>
      <dc:date>2019-11-17T12:34:50Z</dc:date>
    </item>
    <item>
      <title>Re: Smart Event not showing Accepted Log</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-Event-not-showing-Accepted-Log/m-p/67718#M85984</link>
      <description>&lt;P&gt;Very nice! This is exactly what I wanted. Now in SmartEvent I can see statistics of how many connections were made and how much data was transferred. Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 18 Nov 2019 13:20:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-Event-not-showing-Accepted-Log/m-p/67718#M85984</guid>
      <dc:creator>abihsot__</dc:creator>
      <dc:date>2019-11-18T13:20:20Z</dc:date>
    </item>
    <item>
      <title>Re: Smart Event not showing Accepted Log</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-Event-not-showing-Accepted-Log/m-p/112407#M85985</link>
      <description>&lt;P&gt;Does this setting have any effect if enabling in a completely R80 environment? Is it possible, in all R80 environment, to have Firewall logs with type:Control processed by SmartEvent?&lt;/P&gt;</description>
      <pubDate>Wed, 03 Mar 2021 21:37:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-Event-not-showing-Accepted-Log/m-p/112407#M85985</guid>
      <dc:creator>Mark_Metry</dc:creator>
      <dc:date>2021-03-03T21:37:40Z</dc:date>
    </item>
    <item>
      <title>Re: Smart Event not showing Accepted Log</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-Event-not-showing-Accepted-Log/m-p/112412#M85986</link>
      <description>&lt;P&gt;What are you hoping to get out of those logs in particular?&lt;BR /&gt;Yes, the only way they'd get processed by SmartEvent is if that option is enabled.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Mar 2021 22:12:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-Event-not-showing-Accepted-Log/m-p/112412#M85986</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-03-03T22:12:22Z</dc:date>
    </item>
    <item>
      <title>Re: Smart Event not showing Accepted Log</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-Event-not-showing-Accepted-Log/m-p/114365#M85987</link>
      <description>&lt;P&gt;For example, I would like to trigger a correlated event when there is a cluster failover (those logs have type=control).&lt;/P&gt;</description>
      <pubDate>Tue, 23 Mar 2021 13:36:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-Event-not-showing-Accepted-Log/m-p/114365#M85987</guid>
      <dc:creator>Mark_Metry</dc:creator>
      <dc:date>2021-03-23T13:36:25Z</dc:date>
    </item>
  </channel>
</rss>

