<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Search Logs using Domain Name in Src in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Search-Logs-using-Domain-Name-in-Src/m-p/200411#M33450</link>
    <description>&lt;P&gt;Hi mates,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I was wondering if there is any way or workaround to do a search in logs (gathering all my logs on SMS)&lt;/P&gt;&lt;P&gt;using an *.domain_name*&amp;nbsp; as source.&lt;/P&gt;&lt;P&gt;I ve seen another thread with similar question and answer is : "i cant "&amp;nbsp;&lt;/P&gt;&lt;P&gt;But since this was a 2020 topic and we are now almost 4 years after , I was wondering if anything changed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A guess would be that Source in logs is stored with IP only and on SmartConsole when I query them there is a live reverse lookup happening, and that's why i see the names listed in Source, but this information is&amp;nbsp; not stored so i cant use this parameter to search???&lt;/P&gt;&lt;P&gt;Or maybe not...&amp;nbsp; &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyone can help me or take me out of my miserly confirming that there is nothing i can do?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Aris&lt;/P&gt;</description>
    <pubDate>Wed, 13 Dec 2023 09:51:24 GMT</pubDate>
    <dc:creator>zaoar</dc:creator>
    <dc:date>2023-12-13T09:51:24Z</dc:date>
    <item>
      <title>Search Logs using Domain Name in Src</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Search-Logs-using-Domain-Name-in-Src/m-p/200411#M33450</link>
      <description>&lt;P&gt;Hi mates,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I was wondering if there is any way or workaround to do a search in logs (gathering all my logs on SMS)&lt;/P&gt;&lt;P&gt;using an *.domain_name*&amp;nbsp; as source.&lt;/P&gt;&lt;P&gt;I ve seen another thread with similar question and answer is : "i cant "&amp;nbsp;&lt;/P&gt;&lt;P&gt;But since this was a 2020 topic and we are now almost 4 years after , I was wondering if anything changed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A guess would be that Source in logs is stored with IP only and on SmartConsole when I query them there is a live reverse lookup happening, and that's why i see the names listed in Source, but this information is&amp;nbsp; not stored so i cant use this parameter to search???&lt;/P&gt;&lt;P&gt;Or maybe not...&amp;nbsp; &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyone can help me or take me out of my miserly confirming that there is nothing i can do?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Aris&lt;/P&gt;</description>
      <pubDate>Wed, 13 Dec 2023 09:51:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Search-Logs-using-Domain-Name-in-Src/m-p/200411#M33450</guid>
      <dc:creator>zaoar</dc:creator>
      <dc:date>2023-12-13T09:51:24Z</dc:date>
    </item>
    <item>
      <title>Re: Search Logs using Domain Name in Src</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Search-Logs-using-Domain-Name-in-Src/m-p/200485#M33453</link>
      <description>&lt;P&gt;You can only search for src: if the search term resolves to an IP.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Dec 2023 13:37:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Search-Logs-using-Domain-Name-in-Src/m-p/200485#M33453</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-12-13T13:37:40Z</dc:date>
    </item>
    <item>
      <title>Re: Search Logs using Domain Name in Src</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Search-Logs-using-Domain-Name-in-Src/m-p/200496#M33454</link>
      <description>&lt;P&gt;i,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks for reply.&lt;/P&gt;&lt;P&gt;Ok this makes sense&amp;nbsp;&lt;/P&gt;&lt;P&gt;Although a SmartConsole feature to be able to filter src: *domainname* on a list of logs that has been already resolved would be great.&lt;/P&gt;&lt;P&gt;I mean, fore example,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've filtered my logs for a specific timeframe and dst machine in my DMZ network and I am able to see a list of logs with Sources IPs and resolved names. Which is great. All I need now is to filter on top of this result using part of domain name as source.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I mean i realized and tested and works, that if i export the search result to a csv, the domain names are also exported. So I can then do what i need from Excell and find for example if any source *domainname* accessed my DST server.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Aris&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Dec 2023 14:32:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Search-Logs-using-Domain-Name-in-Src/m-p/200496#M33454</guid>
      <dc:creator>zaoar</dc:creator>
      <dc:date>2023-12-13T14:32:45Z</dc:date>
    </item>
  </channel>
</rss>

