<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Alert when utilization is high in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Alert-when-utilization-is-high/m-p/182405#M30433</link>
    <description>&lt;P&gt;One roundabout way you could get this information is via the &lt;STRONG&gt;fw ctl multik print_heavy_conn&lt;/STRONG&gt; command which reads the kernel table &lt;STRONG&gt;heavy_conn_table&lt;/STRONG&gt;&amp;nbsp;containing all current elephant flows, and also those detected for the last 24 hours.&amp;nbsp; There does not seem to be any way to immediately alert when a heavy connection is detected nor is there any logfile of such that you could follow with &lt;STRONG&gt;tail -f&lt;/STRONG&gt;.&amp;nbsp; If you have at least R81.10 or the latest Jumbo HFA for R81/R80.40, another mechanism you can use to show current top connections (not necessarily declared elephants) is the &lt;STRONG&gt;top_conns&lt;/STRONG&gt; command described here:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk172229" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;sk172229: Top Connections Tool&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;So perhaps you could write a script that occasionally runs one of the above commands on your gateway searching for any displayed entries emanating from the subnets/VLANs where your user population is located.&amp;nbsp; This could be done once an hour for &lt;STRONG&gt;top_conns&lt;/STRONG&gt; (which is realtime only) or once a day for &lt;STRONG&gt;fw ctl multik print_heavy_conn&lt;/STRONG&gt;.&amp;nbsp; This solution wouldn't notify you in real time if some user was starting to hog bandwidth and is certainly not perfect, but if they are doing it constantly you will eventually catch them.&amp;nbsp; Both of these great commands are covered and utilized for lab exercises in my &lt;A href="http://www.maxpowerfirewalls.com/gw-optimization-course.html" target="_self"&gt;Gateway Performance Optimization class&lt;/A&gt;.&lt;/P&gt;</description>
    <pubDate>Mon, 29 May 2023 13:45:38 GMT</pubDate>
    <dc:creator>Timothy_Hall</dc:creator>
    <dc:date>2023-05-29T13:45:38Z</dc:date>
    <item>
      <title>Alert when utilization is high</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Alert-when-utilization-is-high/m-p/182230#M30376</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;can we get notification if there any user who consume bandwidth more than 75% for example?&lt;/P&gt;</description>
      <pubDate>Fri, 26 May 2023 08:31:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Alert-when-utilization-is-high/m-p/182230#M30376</guid>
      <dc:creator>handiansudianto</dc:creator>
      <dc:date>2023-05-26T08:31:11Z</dc:date>
    </item>
    <item>
      <title>Re: Alert when utilization is high</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Alert-when-utilization-is-high/m-p/182319#M30383</link>
      <description>&lt;P&gt;I believe its possible with Smart Event, I can check Monday in my lab.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 26 May 2023 20:00:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Alert-when-utilization-is-high/m-p/182319#M30383</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-05-26T20:00:17Z</dc:date>
    </item>
    <item>
      <title>Re: Alert when utilization is high</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Alert-when-utilization-is-high/m-p/182336#M30390</link>
      <description>&lt;P&gt;I checked in my R81.20 lab where I have dedicated SE server and could not find something similar. I also verified in SV monitor (you need that blade enabled for full functionality), but cant seem to find much better there either. Maybe Im just looking at the wrong places...&lt;/P&gt;
&lt;P&gt;Anyway, tagged&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/37178"&gt;@Amir_Senn&lt;/a&gt;&amp;nbsp;, Im positive he will know, as he helped me with similar queries in the past.&lt;/P&gt;
&lt;P&gt;Have a nice weekend!&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sat, 27 May 2023 16:02:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Alert-when-utilization-is-high/m-p/182336#M30390</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-05-27T16:02:47Z</dc:date>
    </item>
    <item>
      <title>Re: Alert when utilization is high</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Alert-when-utilization-is-high/m-p/182350#M30397</link>
      <description>&lt;P&gt;AFAIK, there's no way to alert this.&lt;/P&gt;
&lt;P&gt;We can check amount of data but this could be misleading because it also depends on session time.&lt;/P&gt;
&lt;P&gt;You can limit traffic bandwidth in the rulebase itself if it helps, or analyze the data you already have with SmartView.&lt;/P&gt;</description>
      <pubDate>Sun, 28 May 2023 09:59:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Alert-when-utilization-is-high/m-p/182350#M30397</guid>
      <dc:creator>Amir_Senn</dc:creator>
      <dc:date>2023-05-28T09:59:19Z</dc:date>
    </item>
    <item>
      <title>Re: Alert when utilization is high</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Alert-when-utilization-is-high/m-p/182355#M30398</link>
      <description>&lt;P&gt;Thanks for confirming&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/37178"&gt;@Amir_Senn&lt;/a&gt;&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":thumbs_up:"&gt;👍&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 28 May 2023 12:22:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Alert-when-utilization-is-high/m-p/182355#M30398</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-05-28T12:22:36Z</dc:date>
    </item>
    <item>
      <title>Re: Alert when utilization is high</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Alert-when-utilization-is-high/m-p/182360#M30400</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/37178"&gt;@Amir_Senn&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks you, if this not possible from checkpoint side i will try search if there any 3rd party application which can do this.&lt;/P&gt;</description>
      <pubDate>Mon, 29 May 2023 00:56:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Alert-when-utilization-is-high/m-p/182360#M30400</guid>
      <dc:creator>handiansudianto</dc:creator>
      <dc:date>2023-05-29T00:56:46Z</dc:date>
    </item>
    <item>
      <title>Re: Alert when utilization is high</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Alert-when-utilization-is-high/m-p/182405#M30433</link>
      <description>&lt;P&gt;One roundabout way you could get this information is via the &lt;STRONG&gt;fw ctl multik print_heavy_conn&lt;/STRONG&gt; command which reads the kernel table &lt;STRONG&gt;heavy_conn_table&lt;/STRONG&gt;&amp;nbsp;containing all current elephant flows, and also those detected for the last 24 hours.&amp;nbsp; There does not seem to be any way to immediately alert when a heavy connection is detected nor is there any logfile of such that you could follow with &lt;STRONG&gt;tail -f&lt;/STRONG&gt;.&amp;nbsp; If you have at least R81.10 or the latest Jumbo HFA for R81/R80.40, another mechanism you can use to show current top connections (not necessarily declared elephants) is the &lt;STRONG&gt;top_conns&lt;/STRONG&gt; command described here:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk172229" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;sk172229: Top Connections Tool&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;So perhaps you could write a script that occasionally runs one of the above commands on your gateway searching for any displayed entries emanating from the subnets/VLANs where your user population is located.&amp;nbsp; This could be done once an hour for &lt;STRONG&gt;top_conns&lt;/STRONG&gt; (which is realtime only) or once a day for &lt;STRONG&gt;fw ctl multik print_heavy_conn&lt;/STRONG&gt;.&amp;nbsp; This solution wouldn't notify you in real time if some user was starting to hog bandwidth and is certainly not perfect, but if they are doing it constantly you will eventually catch them.&amp;nbsp; Both of these great commands are covered and utilized for lab exercises in my &lt;A href="http://www.maxpowerfirewalls.com/gw-optimization-course.html" target="_self"&gt;Gateway Performance Optimization class&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Mon, 29 May 2023 13:45:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Alert-when-utilization-is-high/m-p/182405#M30433</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2023-05-29T13:45:38Z</dc:date>
    </item>
  </channel>
</rss>

