<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Under what circumstances a new log is created within the Session unification timeout? in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Under-what-circumstances-a-new-log-is-created-within-the-Session/m-p/108728#M20690</link>
    <description>&lt;P&gt;We work in a BAS technology to test security controls continuously, missing events because of the log suppression (default config) puts us in troubles because our test outcome is filled with false negatives (all suppressed logs)&lt;/P&gt;&lt;P&gt;We would like to know what's the logic behind the creation of a new event under the Session unification timeout (suppressed logs). After some tests we observed that in connections with the same source, destination and application , when an application parameter changes, (like the user agent in an HTTP request) the main event is updated with the new information (user agent), also, the lastupdatetime and the source port, but that does not occur always.&lt;/P&gt;&lt;P&gt;Any documentation or idea here?&lt;/P&gt;</description>
    <pubDate>Mon, 25 Jan 2021 08:13:40 GMT</pubDate>
    <dc:creator>Oscar_Bernat</dc:creator>
    <dc:date>2021-01-25T08:13:40Z</dc:date>
    <item>
      <title>Under what circumstances a new log is created within the Session unification timeout?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Under-what-circumstances-a-new-log-is-created-within-the-Session/m-p/108728#M20690</link>
      <description>&lt;P&gt;We work in a BAS technology to test security controls continuously, missing events because of the log suppression (default config) puts us in troubles because our test outcome is filled with false negatives (all suppressed logs)&lt;/P&gt;&lt;P&gt;We would like to know what's the logic behind the creation of a new event under the Session unification timeout (suppressed logs). After some tests we observed that in connections with the same source, destination and application , when an application parameter changes, (like the user agent in an HTTP request) the main event is updated with the new information (user agent), also, the lastupdatetime and the source port, but that does not occur always.&lt;/P&gt;&lt;P&gt;Any documentation or idea here?&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jan 2021 08:13:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Under-what-circumstances-a-new-log-is-created-within-the-Session/m-p/108728#M20690</guid>
      <dc:creator>Oscar_Bernat</dc:creator>
      <dc:date>2021-01-25T08:13:40Z</dc:date>
    </item>
    <item>
      <title>Re: Under what circumstances a new log is created within the Session unification timeout?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Under-what-circumstances-a-new-log-is-created-within-the-Session/m-p/108959#M20722</link>
      <description>&lt;P&gt;Quoting from &lt;A href="https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_LoggingAndMonitoring_AdminGuide/Topics-LMG/Log-Sessions.htm?Highlight=session" target="_self"&gt;R81 logging and monitoring guide&lt;/A&gt;:&lt;BR /&gt;&lt;BR /&gt;&lt;EM&gt;By default, after a&amp;nbsp;&lt;SPAN class="SearchHighlight SearchHighlight1"&gt;session&lt;/SPAN&gt;&amp;nbsp;continues for three hours, the&amp;nbsp;&lt;SPAN class="mc-variable Other_Vars.tp_sgate variable"&gt;Security Gateway&lt;/SPAN&gt;&amp;nbsp;starts a new&amp;nbsp;&lt;SPAN class="SearchHighlight SearchHighlight1"&gt;session&lt;/SPAN&gt;&amp;nbsp;log. You can change this in&amp;nbsp;&lt;SPAN class="mc-variable Other_Vars.tp_con variable"&gt;SmartConsole&lt;/SPAN&gt;&amp;nbsp;from the&amp;nbsp;&lt;SPAN class="Menu_Options"&gt;&lt;SPAN class="mc-variable Other_Vars.tp_set variable"&gt;Manage &amp;amp; Settings&lt;/SPAN&gt;&lt;/SPAN&gt;&amp;nbsp;view, in&amp;nbsp;&lt;SPAN class="Menu_Options"&gt;Blades&lt;/SPAN&gt;&amp;nbsp;&amp;gt;&amp;nbsp;&lt;SPAN class="Menu_Options"&gt;&lt;SPAN class="mc-variable Vars_BladesFeatures.tp_appurlf variable"&gt;Application &amp;amp; URL Filtering&lt;/SPAN&gt;&lt;/SPAN&gt;&amp;nbsp;&amp;gt;&amp;nbsp;&lt;SPAN class="Menu_Options"&gt;Advanced Settings&lt;/SPAN&gt;&amp;nbsp;&amp;gt;&amp;nbsp;&lt;SPAN class="Menu_Options"&gt;General&lt;/SPAN&gt;&amp;nbsp;&amp;gt;&amp;nbsp;&lt;SPAN class="Menu_Options"&gt;Connection unification&lt;/SPAN&gt;.&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jan 2021 10:51:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Under-what-circumstances-a-new-log-is-created-within-the-Session/m-p/108959#M20722</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2021-01-27T10:51:21Z</dc:date>
    </item>
    <item>
      <title>Re: Under what circumstances a new log is created within the Session unification timeout?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Under-what-circumstances-a-new-log-is-created-within-the-Session/m-p/109252#M20750</link>
      <description>&lt;P&gt;I'm so sorry, my question was related to the Threat Prevention Unification session timeout and the suppressed logs, not about Application and URL filtering. We used the user-agent in the HTTP connection to test and force the generation of new events for a specific threat, in that case, we worked with the simplest one, making a connection to "&lt;A href="http://www.threat-cloud.com/test/files/HighConfidenceBot.html&amp;quot;" target="_blank"&gt;http://www.threat-cloud.com/test/files/HighConfidenceBot.html"&lt;/A&gt;&amp;nbsp;in order to generate a new anti-bot blade event. The question is that depending on the time between every new connection we can see the main event (anti-bot) updated or not. That's why we would like to know the logic behind creating or updating events when suppressed logs feature is enabled (default).&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jan 2021 08:05:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Under-what-circumstances-a-new-log-is-created-within-the-Session/m-p/109252#M20750</guid>
      <dc:creator>Oscar_Bernat</dc:creator>
      <dc:date>2021-01-29T08:05:33Z</dc:date>
    </item>
    <item>
      <title>Re: Under what circumstances a new log is created within the Session unification timeout?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Under-what-circumstances-a-new-log-is-created-within-the-Session/m-p/125903#M23200</link>
      <description>&lt;P&gt;Better late than never to answer this question.&amp;nbsp;&amp;nbsp;All Threat Prevention logs have a suppression period of 10 hours (600 minutes).&lt;BR /&gt;The suppression period restarts upon Threat Prevention policy reinstallation.&amp;nbsp; Source:&amp;nbsp;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk115876&amp;amp;partition=Expert&amp;amp;product=IPS" target="_blank"&gt;sk115876: Some fields are missing from IPS or Threat Prevention logs&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Aug 2021 19:33:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Under-what-circumstances-a-new-log-is-created-within-the-Session/m-p/125903#M23200</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2021-08-06T19:33:03Z</dc:date>
    </item>
  </channel>
</rss>

