<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic External IOC  - Log questions in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/External-IOC-Log-questions/m-p/185369#M30905</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I've been testing out some external IOCs for a production rollout and was hoping to get some understandings on some of the log messages.&amp;nbsp; &amp;nbsp;I have 3 feeds running for testing:&amp;nbsp; &amp;nbsp;one IP host list, one url list and one domain list.&lt;/P&gt;&lt;P&gt;When looking at "blade:Anti-Virus AND type:Control" in smartconsole, I get these logs under the 'forensics Details =&amp;gt; Description" and what my understanding is:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;External IOC - Fetch succeeded&lt;UL&gt;&lt;LI&gt;I know that the configs are setup to fetch the feed every 5min but the log seems to show up only when there was an actual update to the feed txt/csv file on the remote server.&lt;UL&gt;&lt;LI&gt;So....my understanding is when i see this message it means at least 1 of the 3 feeds had an update and such fetch is good.&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;External IOC - Partial success, IP_TEST: Success, URL_TEST: Success, DOMAIN_TEST: Feed format problem. Empty feed"&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;I read this the same as the above message except that one of the feeds had a problem due to the feed having no domains listed (which was the test case).&amp;nbsp; &amp;nbsp; The other two feeds 'fetched'&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;External IOC - External Indicators processing failed&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;This one seems straightforward&amp;nbsp;to me as it detailed out that the processing failed and the reason.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;Our reason was&amp;nbsp;"Couldn't connect to server"; which is accurate during our testing and the remote server was down.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;I also noticed that I got this message every 5 min; which solidifies&amp;nbsp;that the GW was attempting updates within the defined interval.&amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;So.....now my questions &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Is my understanding about these 3 log messages&amp;nbsp;correct?&lt;/LI&gt;&lt;LI&gt;If so, is there any way to get a "External IOC - Fetch succeeded" type message that includes the actual feed that was updated verse getting the general one I got here?&lt;OL&gt;&lt;LI&gt;When I look at the partial success one, I can see the details of all 3 feeds, the 2 that updated and the other one with the error.&amp;nbsp; &amp;nbsp;&lt;/LI&gt;&lt;LI&gt;For our testing, I would like to get a more clear log of the success of the single feed we updated that our SIEM can filter on as a means to know our updates were processed.&lt;OL&gt;&lt;LI&gt;I noticed that "External IOC - Fetch succeeded" messages can get noisy depending on the # of feeds you use; especially on a 3rd party one that might update a lot.&lt;/LI&gt;&lt;LI&gt;Therefore, our key is to have our feed file update =&amp;gt; allow our GWs to fetch every 5min =&amp;gt; log back when the update was successfully updated for the given feed =&amp;gt; avoid the manual labor of logging into various GWs to validate the feed in question updated &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;**note**&lt;/P&gt;&lt;P&gt;GW &amp;amp; MGMT running R81.10 Take 95&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 30 Jun 2023 21:57:02 GMT</pubDate>
    <dc:creator>Scottc98</dc:creator>
    <dc:date>2023-06-30T21:57:02Z</dc:date>
    <item>
      <title>External IOC  - Log questions</title>
      <link>https://community.checkpoint.com/t5/General-Topics/External-IOC-Log-questions/m-p/185369#M30905</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I've been testing out some external IOCs for a production rollout and was hoping to get some understandings on some of the log messages.&amp;nbsp; &amp;nbsp;I have 3 feeds running for testing:&amp;nbsp; &amp;nbsp;one IP host list, one url list and one domain list.&lt;/P&gt;&lt;P&gt;When looking at "blade:Anti-Virus AND type:Control" in smartconsole, I get these logs under the 'forensics Details =&amp;gt; Description" and what my understanding is:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;External IOC - Fetch succeeded&lt;UL&gt;&lt;LI&gt;I know that the configs are setup to fetch the feed every 5min but the log seems to show up only when there was an actual update to the feed txt/csv file on the remote server.&lt;UL&gt;&lt;LI&gt;So....my understanding is when i see this message it means at least 1 of the 3 feeds had an update and such fetch is good.&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;External IOC - Partial success, IP_TEST: Success, URL_TEST: Success, DOMAIN_TEST: Feed format problem. Empty feed"&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;I read this the same as the above message except that one of the feeds had a problem due to the feed having no domains listed (which was the test case).&amp;nbsp; &amp;nbsp; The other two feeds 'fetched'&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;External IOC - External Indicators processing failed&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;This one seems straightforward&amp;nbsp;to me as it detailed out that the processing failed and the reason.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;Our reason was&amp;nbsp;"Couldn't connect to server"; which is accurate during our testing and the remote server was down.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;I also noticed that I got this message every 5 min; which solidifies&amp;nbsp;that the GW was attempting updates within the defined interval.&amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;So.....now my questions &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Is my understanding about these 3 log messages&amp;nbsp;correct?&lt;/LI&gt;&lt;LI&gt;If so, is there any way to get a "External IOC - Fetch succeeded" type message that includes the actual feed that was updated verse getting the general one I got here?&lt;OL&gt;&lt;LI&gt;When I look at the partial success one, I can see the details of all 3 feeds, the 2 that updated and the other one with the error.&amp;nbsp; &amp;nbsp;&lt;/LI&gt;&lt;LI&gt;For our testing, I would like to get a more clear log of the success of the single feed we updated that our SIEM can filter on as a means to know our updates were processed.&lt;OL&gt;&lt;LI&gt;I noticed that "External IOC - Fetch succeeded" messages can get noisy depending on the # of feeds you use; especially on a 3rd party one that might update a lot.&lt;/LI&gt;&lt;LI&gt;Therefore, our key is to have our feed file update =&amp;gt; allow our GWs to fetch every 5min =&amp;gt; log back when the update was successfully updated for the given feed =&amp;gt; avoid the manual labor of logging into various GWs to validate the feed in question updated &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;**note**&lt;/P&gt;&lt;P&gt;GW &amp;amp; MGMT running R81.10 Take 95&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Jun 2023 21:57:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/External-IOC-Log-questions/m-p/185369#M30905</guid>
      <dc:creator>Scottc98</dc:creator>
      <dc:date>2023-06-30T21:57:02Z</dc:date>
    </item>
    <item>
      <title>Re: External IOC  - Log questions</title>
      <link>https://community.checkpoint.com/t5/General-Topics/External-IOC-Log-questions/m-p/185376#M30908</link>
      <description>&lt;P&gt;As far as I know, you have a clear understanding of this.&lt;BR /&gt;Unfortunately, I don't believe you can change the detail of the logging about what feeds were updated.&lt;BR /&gt;It's possible this is improved in R81.20 where we can support a larger number of indicators and Network Feeds are an option.&lt;/P&gt;</description>
      <pubDate>Sat, 01 Jul 2023 15:40:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/External-IOC-Log-questions/m-p/185376#M30908</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-07-01T15:40:45Z</dc:date>
    </item>
  </channel>
</rss>

