<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Alert about increase in a specific type of log (&amp;quot;First packet isn't SYN&amp;quot;  for me) in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Alert-about-increase-in-a-specific-type-of-log-quot-First-packet/m-p/240051#M40061</link>
    <description>&lt;P&gt;Thank you very much, exactly what I was looking for!&lt;/P&gt;</description>
    <pubDate>Thu, 30 Jan 2025 08:50:32 GMT</pubDate>
    <dc:creator>bob111</dc:creator>
    <dc:date>2025-01-30T08:50:32Z</dc:date>
    <item>
      <title>Alert about increase in a specific type of log ("First packet isn't SYN"  for me)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Alert-about-increase-in-a-specific-type-of-log-quot-First-packet/m-p/239971#M40055</link>
      <description>&lt;P&gt;Hello guys,&lt;BR /&gt;I have a firewall gateway cluster&amp;nbsp; with a manager, version 81.10. I am looking for ways to get an alert about an increase of the log "First packet isn't SYN", whether it is with skyline or some other alert mechanism, through the api or even a cli command that would let me do a query on the logs.&lt;BR /&gt;If anyone has suggestions I would love to hear. Thanks:)&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2025 13:35:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Alert-about-increase-in-a-specific-type-of-log-quot-First-packet/m-p/239971#M40055</guid>
      <dc:creator>bob111</dc:creator>
      <dc:date>2025-01-29T13:35:44Z</dc:date>
    </item>
    <item>
      <title>Re: Alert about increase in a specific type of log ("First packet isn't SYN"  for me)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Alert-about-increase-in-a-specific-type-of-log-quot-First-packet/m-p/239992#M40056</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/85840"&gt;@bob111&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;I suggest you to upgrade it to R81.20 because the support of R81.10 will expired soon. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/LI&gt;
&lt;LI&gt;Are you sending the logs to any kind SIEM?&lt;/LI&gt;
&lt;LI&gt;Have you checked the features of the SmartEvent?
&lt;UL&gt;
&lt;LI&gt;I am not 100% sure, maybe you can set such kind of threshold there&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Akos&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&amp;nbsp;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Wed, 29 Jan 2025 16:57:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Alert-about-increase-in-a-specific-type-of-log-quot-First-packet/m-p/239992#M40056</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2025-01-29T16:57:38Z</dc:date>
    </item>
    <item>
      <title>Re: Alert about increase in a specific type of log ("First packet isn't SYN"  for me)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Alert-about-increase-in-a-specific-type-of-log-quot-First-packet/m-p/240029#M40058</link>
      <description>&lt;P&gt;If it shows up in a search (e.g. with SmartView), you can query via API here:&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/latest/APIs/index.html#cli/show-logs~v2%20" target="_blank"&gt;https://sc1.checkpoint.com/documents/latest/APIs/index.html#cli/show-logs~v2%20&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;Whether these kinds of messages are "indexed" or not is a separate question.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jan 2025 03:24:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Alert-about-increase-in-a-specific-type-of-log-quot-First-packet/m-p/240029#M40058</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-01-30T03:24:26Z</dc:date>
    </item>
    <item>
      <title>Re: Alert about increase in a specific type of log ("First packet isn't SYN"  for me)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Alert-about-increase-in-a-specific-type-of-log-quot-First-packet/m-p/240051#M40061</link>
      <description>&lt;P&gt;Thank you very much, exactly what I was looking for!&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jan 2025 08:50:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Alert-about-increase-in-a-specific-type-of-log-quot-First-packet/m-p/240051#M40061</guid>
      <dc:creator>bob111</dc:creator>
      <dc:date>2025-01-30T08:50:32Z</dc:date>
    </item>
  </channel>
</rss>

