<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Question about log records in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Question-about-log-records/m-p/117772#M21922</link>
    <description>&lt;P&gt;QoS wouldn’t apply until after traffic was accepted by an Access Policy rule.&lt;BR /&gt;However, what you’re describing suggests either the accepting rule isn’t being logged or the relevant log was consolidated into a session where the start date/time is different (this doesn’t appear together).&lt;/P&gt;
&lt;P&gt;Might be worth a TAC case to have them investigate.&lt;/P&gt;</description>
    <pubDate>Wed, 05 May 2021 19:10:11 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2021-05-05T19:10:11Z</dc:date>
    <item>
      <title>Question about log records</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Question-about-log-records/m-p/117741#M21916</link>
      <description>&lt;P&gt;Hey,&lt;BR /&gt;I couldn't find anywhere answer so I will ask here a silly question about log records. Sometimes in logs (via Logs &amp;amp; Monitor) I can see that in Blade column there are values like Multiple Blades (QoS with Firewall) or some single blades - QoS or Firewall.&lt;BR /&gt;When record contains Firewall blade then I can get the rule number via which user accessed some resources. But in some records there is only QoS blade - log details shows src IP, dst IP, ports, action etc., but there is no rule number. If the action was "Accept" does it mean that user accessed the destination at the time the QoS record was recorded, even if there are no records from Firewall blade?&lt;BR /&gt;I have no idea how to interpret that kind of log records &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt; Maybe you could enlighten me.&lt;/P&gt;</description>
      <pubDate>Wed, 05 May 2021 12:24:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Question-about-log-records/m-p/117741#M21916</guid>
      <dc:creator>Bernard</dc:creator>
      <dc:date>2021-05-05T12:24:39Z</dc:date>
    </item>
    <item>
      <title>Re: Question about log records</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Question-about-log-records/m-p/117772#M21922</link>
      <description>&lt;P&gt;QoS wouldn’t apply until after traffic was accepted by an Access Policy rule.&lt;BR /&gt;However, what you’re describing suggests either the accepting rule isn’t being logged or the relevant log was consolidated into a session where the start date/time is different (this doesn’t appear together).&lt;/P&gt;
&lt;P&gt;Might be worth a TAC case to have them investigate.&lt;/P&gt;</description>
      <pubDate>Wed, 05 May 2021 19:10:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Question-about-log-records/m-p/117772#M21922</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-05-05T19:10:11Z</dc:date>
    </item>
  </channel>
</rss>

