<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic fw log Format(accept, drop, reject) in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-log-Format-accept-drop-reject/m-p/24832#M89486</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am trying to find fw log format in order to parsing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I got logs but I don't know each field meaning.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;also accept log and drop log are different.( field )&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;BLOCKQUOTE class="jive_macro_quote jive-quote jive_text_macro"&gt;&lt;P&gt;[Expert@gw-18ee86:0]# fw log -n -p -c accept&lt;BR /&gt; Date: Jan 16, 2019&lt;BR /&gt; 8:07:08 5 N/A 1 accept 172.31.6.61 &amp;gt; N/A LogId: &amp;lt;max_null&amp;gt;; ContextNum: &amp;lt;max_null&amp;gt;; OriginSicName: cn=cp_mgmt,o=gw-18ee86..hu5ufg; OriginSicName: cn=cp_mgmt,o=gw-18ee86..hu5ufg; HighLevelLogKey: 18446744073709551615; rule_guid: {4A3B1474-A403-4742-893D-E501A5C5C5B0}; hit: 3; policy: fw1; first_hit_time: 1547593568; last_hit_time: 1547593621; log_id: 10; ProductName: VPN-1 &amp;amp; FireWall-1; ProductFamily: Network;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[Expert@gw-18ee86:0]# fw log -n -p -c drop&lt;BR /&gt; Date: Jan 16, 2019&lt;BR /&gt; 8:06:10 5 N/A 1 drop 172.31.6.61 &amp;gt; eth0 LogId: 1; ContextNum: &amp;lt;max_null&amp;gt;; OriginSicName: cn=cp_mgmt,o=gw-18ee86..hu5ufg; OriginSicName: cn=cp_mgmt,o=gw-18ee86..hu5ufg; HighLevelLogKey: 18446744073709551615; TCP packet out of state: Server to client packet of an old TCP connection; tcp_flags: RST; src: 172.31.6.61; dst: 182.50.136.237; proto: tcp; ProductName: VPN-1 &amp;amp; FireWall-1; svc: 80; sport_svc: 44036; ProductFamily: Network;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;anyone have log format document?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thank you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 16 Jan 2019 08:01:23 GMT</pubDate>
    <dc:creator>yongjun_jin</dc:creator>
    <dc:date>2019-01-16T08:01:23Z</dc:date>
    <item>
      <title>fw log Format(accept, drop, reject)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-log-Format-accept-drop-reject/m-p/24832#M89486</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am trying to find fw log format in order to parsing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I got logs but I don't know each field meaning.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;also accept log and drop log are different.( field )&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;BLOCKQUOTE class="jive_macro_quote jive-quote jive_text_macro"&gt;&lt;P&gt;[Expert@gw-18ee86:0]# fw log -n -p -c accept&lt;BR /&gt; Date: Jan 16, 2019&lt;BR /&gt; 8:07:08 5 N/A 1 accept 172.31.6.61 &amp;gt; N/A LogId: &amp;lt;max_null&amp;gt;; ContextNum: &amp;lt;max_null&amp;gt;; OriginSicName: cn=cp_mgmt,o=gw-18ee86..hu5ufg; OriginSicName: cn=cp_mgmt,o=gw-18ee86..hu5ufg; HighLevelLogKey: 18446744073709551615; rule_guid: {4A3B1474-A403-4742-893D-E501A5C5C5B0}; hit: 3; policy: fw1; first_hit_time: 1547593568; last_hit_time: 1547593621; log_id: 10; ProductName: VPN-1 &amp;amp; FireWall-1; ProductFamily: Network;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[Expert@gw-18ee86:0]# fw log -n -p -c drop&lt;BR /&gt; Date: Jan 16, 2019&lt;BR /&gt; 8:06:10 5 N/A 1 drop 172.31.6.61 &amp;gt; eth0 LogId: 1; ContextNum: &amp;lt;max_null&amp;gt;; OriginSicName: cn=cp_mgmt,o=gw-18ee86..hu5ufg; OriginSicName: cn=cp_mgmt,o=gw-18ee86..hu5ufg; HighLevelLogKey: 18446744073709551615; TCP packet out of state: Server to client packet of an old TCP connection; tcp_flags: RST; src: 172.31.6.61; dst: 182.50.136.237; proto: tcp; ProductName: VPN-1 &amp;amp; FireWall-1; svc: 80; sport_svc: 44036; ProductFamily: Network;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;anyone have log format document?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thank you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Jan 2019 08:01:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-log-Format-accept-drop-reject/m-p/24832#M89486</guid>
      <dc:creator>yongjun_jin</dc:creator>
      <dc:date>2019-01-16T08:01:23Z</dc:date>
    </item>
    <item>
      <title>Re: fw log Format(accept, drop, reject)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-log-Format-accept-drop-reject/m-p/24833#M89487</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The first line is not an actual log line but an update for the hitcounter.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Jan 2019 13:12:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-log-Format-accept-drop-reject/m-p/24833#M89487</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2019-01-16T13:12:56Z</dc:date>
    </item>
    <item>
      <title>Re: fw log Format(accept, drop, reject)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-log-Format-accept-drop-reject/m-p/24834#M89488</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Am curious why you are trying to use fw log to consume logs.&lt;/P&gt;&lt;P&gt;If you're trying to get the logs to a different system to view them, maybe you should use &lt;A href="https://community.checkpoint.com/message/16349"&gt;Log Exporter guide&lt;/A&gt;&amp;nbsp;instead?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Jan 2019 03:02:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-log-Format-accept-drop-reject/m-p/24834#M89488</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-01-17T03:02:20Z</dc:date>
    </item>
  </channel>
</rss>

