<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Log Filtering Issues in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Filtering-Issues/m-p/10141#M94016</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Carlos&lt;/P&gt;&lt;P&gt;I also notice the SmartLog search function are not perfect, I found some field data&amp;nbsp;can't be searched.&lt;/P&gt;&lt;P&gt;So I only use the&amp;nbsp;field what I known how to use to search.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Because it is not perfect, so we need to suggest CheckPoint to improve it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 18 Jul 2018 14:44:30 GMT</pubDate>
    <dc:creator>RickLin</dc:creator>
    <dc:date>2018-07-18T14:44:30Z</dc:date>
    <item>
      <title>Log Filtering Issues</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Filtering-Issues/m-p/10136#M94011</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'd like to post this query before I move to support, maybe I'm doing/assuming something wrong here.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So a very simple log filter query "domain"&lt;/P&gt;&lt;P&gt;Searching shows a lot of information...&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/67097_pastedImage_2.png" /&gt;&lt;/P&gt;&lt;P&gt;Now let's use "domain-udp"&lt;/P&gt;&lt;P&gt;comparing domain with domain-udp, domain-udp is, to me, more specific than just domain, right? ...Wrong?&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-2 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/67098_pastedImage_3.png" /&gt;&lt;/P&gt;&lt;P&gt;I would say, this is a typical WTF?! question, but as I said above, maybe I'm doing/assuming something wrong with this search filter.&lt;/P&gt;&lt;P&gt;I narrowed down the time to get the highlighted dropped domain-udp sessions from the previous search.&lt;/P&gt;&lt;P&gt;The only difference I notice is the log type: the geo drops are marked as "log" were as for the matched rules are type: connection, but still we have a drop in the middle that hits the clean-up rule 180.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can anyone explain to me, or is this really a support issue?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Carlos&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Jul 2018 10:50:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Filtering-Issues/m-p/10136#M94011</guid>
      <dc:creator>MrSaintz</dc:creator>
      <dc:date>2018-07-18T10:50:02Z</dc:date>
    </item>
    <item>
      <title>Re: Log Filtering Issues</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Filtering-Issues/m-p/10137#M94012</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;May have something to do with the word "domain" contained in the "description" field:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/67102_pastedImage_1.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want to have more accurate results, search with "service:" prefix:&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-2 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/67103_pastedImage_2.png" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Jul 2018 12:48:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Filtering-Issues/m-p/10137#M94012</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2018-07-18T12:48:39Z</dc:date>
    </item>
    <item>
      <title>Re: Log Filtering Issues</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Filtering-Issues/m-p/10138#M94013</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;DIV style="border: 0px; font-weight: inherit; font-size: 14px;"&gt;&lt;DIV class="" style="border: 0px; font-weight: inherit; margin: 20px 0px;"&gt;&lt;P style="border: 0px; font-weight: inherit;"&gt;At the same time.&lt;/P&gt;&lt;P style="border: 0px; font-weight: inherit;"&gt;If you know the service port number what you looking for, you can use "port:".&lt;/P&gt;&lt;P style="border: 0px; font-weight: inherit;"&gt;&lt;IMG class="image-1 jive-image" height="304" src="https://community.checkpoint.com/legacyfs/online/checkpoint/67106_pastedImage_1.png" style="border: 0px; font-weight: inherit; margin: 2px 20px 0px;" width="1129" /&gt;&lt;/P&gt;&lt;P style="border: 0px; font-weight: inherit;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="border: 0px; font-weight: inherit;"&gt;You also can reference the CheckPoint SmartConsole online help about SmartView query language.&amp;nbsp;&lt;/P&gt;&lt;P style="border: 0px; font-weight: inherit;"&gt;&lt;A class="" href="https://sc1.checkpoint.com/documents/R80.10/SmartConsole_OLH/EN/html_frameset.htm?topic=zfFmGvPiAIUaJhQr-pxhDQ2" rel="nofollow" style="color: #6d6e71; border: 0px; font-weight: inherit; text-decoration: none; padding: 0px calc(12px + 0.35ex) 0px 0px;"&gt;SmartConsole R80.10 Help&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV style="border: 0px; font-weight: inherit; font-size: 14px;"&gt; &lt;/DIV&gt;&lt;DIV class="" style="border: 0px; font-weight: inherit; font-size: 14px; margin: 20px 0px 0px;"&gt;&lt;DIV class="" data-comment-id="23501" style="color: #6d6e71; border: none; font-weight: inherit; font-size: 0.8571rem;"&gt; &lt;/DIV&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Jul 2018 14:09:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Filtering-Issues/m-p/10138#M94013</guid>
      <dc:creator>RickLin</dc:creator>
      <dc:date>2018-07-18T14:09:07Z</dc:date>
    </item>
    <item>
      <title>Re: Log Filtering Issues</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Filtering-Issues/m-p/10139#M94014</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you Vladimir,&lt;/P&gt;&lt;P&gt;That was my assumption, but if you look at the screen shots, searching for domain matches much less records then searching for domain-udp, not the other way around...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Searching for specific fields, yes I understand, and it does narrow down to some degree, however it can narrow down too much for troubleshooting, consider asymmetric routing, we want to search for specific traffic on the service, and on the source port, one good trick I confidently used until now was, not specifying the fields in which I want to search for the flow, and hoped it would match more records than big query strings using 'or'/'and' for specific fields.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.checkpoint.com/migrated-users/3134"&gt;Rick Lin&lt;/A&gt;‌,&lt;/P&gt;&lt;P&gt;Thank you for the input around the "port:" field,&amp;nbsp; I did use the help to check for the query language the problem in the help file is that you always mention fields attached to a query string, however you also allow a simple string query.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My clarification request from this point on is:&lt;/P&gt;&lt;P&gt;What fields are used in a log filter search, when not field is specified? And can anyone explain to me how can "domain" match less then "domain-udp" in such scenario?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Carlos Santos&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Jul 2018 14:28:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Filtering-Issues/m-p/10139#M94014</guid>
      <dc:creator>MrSaintz</dc:creator>
      <dc:date>2018-07-18T14:28:56Z</dc:date>
    </item>
    <item>
      <title>Re: Log Filtering Issues</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Filtering-Issues/m-p/10140#M94015</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Did you try domain* instead of just domain? Might do the trick. But of course it seems there is a minor issue with the search tool&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Jul 2018 14:44:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Filtering-Issues/m-p/10140#M94015</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2018-07-18T14:44:10Z</dc:date>
    </item>
    <item>
      <title>Re: Log Filtering Issues</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Filtering-Issues/m-p/10141#M94016</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Carlos&lt;/P&gt;&lt;P&gt;I also notice the SmartLog search function are not perfect, I found some field data&amp;nbsp;can't be searched.&lt;/P&gt;&lt;P&gt;So I only use the&amp;nbsp;field what I known how to use to search.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Because it is not perfect, so we need to suggest CheckPoint to improve it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Jul 2018 14:44:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Filtering-Issues/m-p/10141#M94016</guid>
      <dc:creator>RickLin</dc:creator>
      <dc:date>2018-07-18T14:44:30Z</dc:date>
    </item>
    <item>
      <title>Re: Log Filtering Issues</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Filtering-Issues/m-p/10142#M94017</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Carlos,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This may be an issue with implied delimiter: In the screen caps in my previous post, the OU=Domain is probably being recognized as a standalone "domain" in search string, whereas "domain*" will read "domain-udp".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Searching with prefix "service" using "domain" returns nothing:&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/67109_pastedImage_1.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;While doing same with "domain*" actually yields results containing "domain-udp":&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-2 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/67110_pastedImage_2.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So this reflects the results discrepancy you are seeing.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Jul 2018 15:02:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Filtering-Issues/m-p/10142#M94017</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2018-07-18T15:02:09Z</dc:date>
    </item>
    <item>
      <title>Re: Log Filtering Issues</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Filtering-Issues/m-p/10143#M94018</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It does help Valeri, thank you for the heads-up, i guess i need to use more wildcard options from now on.&lt;/P&gt;&lt;P&gt;In the end the purpose of a log filter search is to to troubleshoot for specific flow conditions, if one cannot feel confident on the search results, troubleshooting is limited right from the start.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Jul 2018 15:13:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Filtering-Issues/m-p/10143#M94018</guid>
      <dc:creator>MrSaintz</dc:creator>
      <dc:date>2018-07-18T15:13:51Z</dc:date>
    </item>
    <item>
      <title>Re: Log Filtering Issues</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Filtering-Issues/m-p/10144#M94019</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think you narrowed down to issue, it does seem to implied delimiter, I only thought that "-" should affect it the same way (as a delimiter) maybe we need to figure out what is forcefully excluded in any search, but then again wildcard does perform very well.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Jul 2018 15:20:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Filtering-Issues/m-p/10144#M94019</guid>
      <dc:creator>MrSaintz</dc:creator>
      <dc:date>2018-07-18T15:20:05Z</dc:date>
    </item>
    <item>
      <title>Re: Log Filtering Issues</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Filtering-Issues/m-p/10145#M94020</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you Rick, to be true nothing is that "perfect", but one needs to feel confident of the used tools in hand to help your customers, right? &lt;IMG src="https://community.checkpoint.com/legacyfs/online/checkpoint/emoticons/wink.png" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Jul 2018 15:21:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Log-Filtering-Issues/m-p/10145#M94020</guid>
      <dc:creator>MrSaintz</dc:creator>
      <dc:date>2018-07-18T15:21:20Z</dc:date>
    </item>
  </channel>
</rss>

