<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Question Log in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Question-Log/m-p/275968#M46063</link>
    <description>&lt;P&gt;We will have the "Session" tab, and detailed information from the relevant connection logs after enabling the "per session" option.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="log_example_1.png" style="width: 769px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/34085i833434D5DD4774B5/image-size/large?v=v2&amp;amp;px=999" role="button" title="log_example_1.png" alt="log_example_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It does not reduce the log volume or make the troubleshooting more difficult.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 23 Apr 2026 07:26:16 GMT</pubDate>
    <dc:creator>tankp</dc:creator>
    <dc:date>2026-04-23T07:26:16Z</dc:date>
    <item>
      <title>Question Log</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Question-Log/m-p/274577#M45919</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi mates,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;hope you’re all doing well.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I have a question regarding logging.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;What are the main benefits of switching from Connection to Session log mode?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;My understanding is that this feature aggregates multiple logs from the same connection into a single session log, reducing the overall log volume.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;However, I’d like to clarify if any details are lost in the session log compared to connection logs. Are all the same fields still available, or is some information not recorded?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Also, could this approach make troubleshooting more challenging in certain scenarios?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Please feel free to correct me if anything is inaccurate or incomplete.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks in advance!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 31 Mar 2026 17:17:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Question-Log/m-p/274577#M45919</guid>
      <dc:creator>RemoteUser</dc:creator>
      <dc:date>2026-03-31T17:17:09Z</dc:date>
    </item>
    <item>
      <title>Re: Question Log</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Question-Log/m-p/274578#M45920</link>
      <description>&lt;P&gt;Hey brother,&lt;/P&gt;
&lt;P&gt;FWIW, this is what AI says.&lt;/P&gt;
&lt;P&gt;*********************************************************&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You’ve got the core idea right &lt;span class="lia-unicode-emoji" title=":thumbs_up:"&gt;👍&lt;/span&gt; — but there are some important nuances that matter in real-world troubleshooting.&lt;/P&gt;
&lt;HR /&gt;
&lt;H2&gt;&lt;span class="lia-unicode-emoji" title=":counterclockwise_arrows_button:"&gt;🔄&lt;/span&gt; Connection vs Session Logging (Quick Context)&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Connection logging&lt;/STRONG&gt; → one log per connection (SYN → FIN lifecycle)&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Session logging&lt;/STRONG&gt; → aggregates multiple connections into a single “session” (based on App/User/IP over time)&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Think of session logs as a &lt;STRONG&gt;summary view&lt;/STRONG&gt;, not a 1:1 replacement.&lt;/P&gt;
&lt;HR /&gt;
&lt;H2&gt;&lt;span class="lia-unicode-emoji" title=":white_heavy_check_mark:"&gt;✅&lt;/span&gt; Main Benefits of Session Logging&lt;/H2&gt;
&lt;H3&gt;1. &lt;span class="lia-unicode-emoji" title=":chart_decreasing:"&gt;📉&lt;/span&gt; Massive Log Volume Reduction&lt;/H3&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;Instead of thousands of short-lived connections (especially with web apps), you get &lt;STRONG&gt;one consolidated session&lt;/STRONG&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Huge win for:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;Log storage&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;SIEM ingestion costs&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;SmartConsole performance&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;HR /&gt;
&lt;H3&gt;2. &lt;span class="lia-unicode-emoji" title=":bust_in_silhouette:"&gt;👤&lt;/span&gt; Better User/Application Visibility&lt;/H3&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;Session logs are &lt;STRONG&gt;identity-aware&lt;/STRONG&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;You see:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;User (via Identity Awareness)&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Application (App Control)&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Overall activity in a session&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":backhand_index_pointing_right:"&gt;👉&lt;/span&gt; This is especially useful for SaaS/web browsing visibility.&lt;/P&gt;
&lt;HR /&gt;
&lt;H3&gt;3. &lt;span class="lia-unicode-emoji" title=":bar_chart:"&gt;📊&lt;/span&gt; Cleaner, High-Level View&lt;/H3&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;Easier to answer:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;“What did user X do?”&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;“What apps were accessed?”&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Instead of digging through hundreds of TCP connections&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;HR /&gt;
&lt;H2&gt;&lt;span class="lia-unicode-emoji" title=":warning:"&gt;⚠️&lt;/span&gt; What You LOSE (Important)&lt;/H2&gt;
&lt;P&gt;Yes — &lt;STRONG&gt;some granularity is lost&lt;/STRONG&gt;.&lt;/P&gt;
&lt;H3&gt;&lt;span class="lia-unicode-emoji" title=":magnifying_glass_tilted_left:"&gt;🔍&lt;/span&gt; Missing / Reduced Detail&lt;/H3&gt;
&lt;OL&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Per-connection visibility&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;You won’t see every TCP handshake or individual connection&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Example: multiple HTTP requests → one session log&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Precise timing per connection&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;Session log shows duration, but not each micro-event&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Low-level network troubleshooting data&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;Harder to track:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;Packet-level issues&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Connection resets/retries&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;NAT edge cases per connection&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;HR /&gt;
&lt;H2&gt;🧠 Troubleshooting Impact&lt;/H2&gt;
&lt;H3&gt;&lt;span class="lia-unicode-emoji" title=":thumbs_up:"&gt;👍&lt;/span&gt; Easier for:&lt;/H3&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;User activity analysis&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Application usage&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;General traffic patterns&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3&gt;&lt;span class="lia-unicode-emoji" title=":thumbs_down:"&gt;👎&lt;/span&gt; Harder for:&lt;/H3&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;Deep network debugging&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Intermittent connection issues&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Protocol-level problems&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":backhand_index_pointing_right:"&gt;👉&lt;/span&gt; In those cases, &lt;STRONG&gt;connection logs are superior&lt;/STRONG&gt;&lt;/P&gt;
&lt;HR /&gt;
&lt;H2&gt;&lt;span class="lia-unicode-emoji" title=":balance_scale:"&gt;⚖️&lt;/span&gt; Real-World Best Practice&lt;/H2&gt;
&lt;P&gt;Most environments don’t go “all-in” on one mode.&lt;/P&gt;
&lt;H3&gt;Common approach:&lt;/H3&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;Use &lt;STRONG&gt;Session logging&lt;/STRONG&gt; for:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;Web traffic&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;SaaS / user-based rules&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Keep &lt;STRONG&gt;Connection logging&lt;/STRONG&gt; for:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;Critical infrastructure&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;VPN / NAT-heavy rules&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Troubleshooting-sensitive policies&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;HR /&gt;
&lt;H2&gt;&lt;span class="lia-unicode-emoji" title=":wrench:"&gt;🔧&lt;/span&gt; Key Insight (Often Missed)&lt;/H2&gt;
&lt;P&gt;Session logs are &lt;STRONG&gt;built from connection logs internally&lt;/STRONG&gt;, but:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;Not all connection-level events are preserved in the final log&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;It’s more like &lt;STRONG&gt;aggregation + summarization&lt;/STRONG&gt;, not full fidelity storage&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;HR /&gt;
&lt;H2&gt;🧩 When NOT to Use Session Logging&lt;/H2&gt;
&lt;P&gt;Avoid it if you rely heavily on:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;Detailed forensics&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Packet/flow-level debugging&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Regulatory requirements needing full connection traceability&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;HR /&gt;
&lt;H2&gt;&lt;span class="lia-unicode-emoji" title=":heavy_check_mark:"&gt;✔️&lt;/span&gt; Bottom Line&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;Your understanding is correct &lt;span class="lia-unicode-emoji" title=":white_heavy_check_mark:"&gt;✅&lt;/span&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Big win:&lt;/STRONG&gt; reduced log volume + better user/app visibility&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Tradeoff:&lt;/STRONG&gt; loss of per-connection granularity&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Impact:&lt;/STRONG&gt; can make deep troubleshooting harder&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;HR /&gt;
&lt;P&gt;If you want, I can break this down specifically for &lt;STRONG&gt;Check Point R81/R82 behavior&lt;/STRONG&gt; (there are a couple of quirks with HTTPS inspection and App Control that affect session logs).&lt;/P&gt;</description>
      <pubDate>Tue, 31 Mar 2026 17:27:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Question-Log/m-p/274578#M45920</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2026-03-31T17:27:36Z</dc:date>
    </item>
    <item>
      <title>Re: Question Log</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Question-Log/m-p/274603#M45925</link>
      <description>&lt;P&gt;I didn't know that if you switch to “session” mode, certain fields like “nat” are lost if it's used...&lt;/P&gt;</description>
      <pubDate>Wed, 01 Apr 2026 07:56:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Question-Log/m-p/274603#M45925</guid>
      <dc:creator>RemoteUser</dc:creator>
      <dc:date>2026-04-01T07:56:29Z</dc:date>
    </item>
    <item>
      <title>Re: Question Log</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Question-Log/m-p/274656#M45933</link>
      <description>&lt;P&gt;The issue with NAT was fixed recently as described here:&amp;nbsp;&lt;SPAN class="s1"&gt;&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/Session-logs-not-showing-Xlate-information/m-p/149711/highlight/true#M24091" target="_blank"&gt;https://community.checkpoint.com/t5/Security-Gateways/Session-logs-not-showing-Xlate-information/m-p/149711/highlight/true#M24091&lt;/A&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Apr 2026 14:29:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Question-Log/m-p/274656#M45933</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2026-04-01T14:29:59Z</dc:date>
    </item>
    <item>
      <title>Re: Question Log</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Question-Log/m-p/275968#M46063</link>
      <description>&lt;P&gt;We will have the "Session" tab, and detailed information from the relevant connection logs after enabling the "per session" option.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="log_example_1.png" style="width: 769px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/34085i833434D5DD4774B5/image-size/large?v=v2&amp;amp;px=999" role="button" title="log_example_1.png" alt="log_example_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It does not reduce the log volume or make the troubleshooting more difficult.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Apr 2026 07:26:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Question-Log/m-p/275968#M46063</guid>
      <dc:creator>tankp</dc:creator>
      <dc:date>2026-04-23T07:26:16Z</dc:date>
    </item>
  </channel>
</rss>

