<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Mismatch in Infinity Portal's Infinity Event logs in Events</title>
    <link>https://community.checkpoint.com/t5/Events/Mismatch-in-Infinity-Portal-s-Infinity-Event-logs/m-p/226830#M43</link>
    <description>&lt;P&gt;"&lt;SPAN&gt;9/9/2024 12:00 AM to 9/10/2024 01:00 AM it says it has around 5 million logs" represents a 25 hour timeframe versus a 1 hour timeframe.&lt;BR /&gt;That might explain why these numbers are so far off.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 16 Sep 2024 16:56:32 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2024-09-16T16:56:32Z</dc:date>
    <item>
      <title>Mismatch in Infinity Portal's Infinity Event logs</title>
      <link>https://community.checkpoint.com/t5/Events/Mismatch-in-Infinity-Portal-s-Infinity-Event-logs/m-p/226804#M42</link>
      <description>&lt;P&gt;Hello everyone, I'm encountering a peculiar situation on Infinity Portal's Infinity Events tab.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Q1:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;As you can see in the picture, I have selected a random day of security event logs to inspect. On the time range 9/9/2024 12:00 AM to 9/9/2024&amp;nbsp;01:00 AM (&lt;STRONG&gt;*Fixed typo that previously said "&lt;SPAN&gt;9/9/2024 12:00 AM to 9/10/2024 01:00 AM it says it has around 5 million logs"&lt;/SPAN&gt;&amp;nbsp;*)&lt;/STRONG&gt;&amp;nbsp;it says it has around 5 million logs. &lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="logs in a day.png" style="width: 399px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/27647iFDBA1222E1498C20/image-dimensions/399x266?v=v2" width="399" height="266" role="button" title="logs in a day.png" alt="logs in a day.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;However, if I click on the first column, that represents the logs in that day, from 12:00 AM to 01:00 AM, I get this:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="logs in an hour.png" style="width: 447px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/27648iF151B29860621889/image-dimensions/447x210?v=v2" width="447" height="210" role="button" title="logs in an hour.png" alt="logs in an hour.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;The statistics graph shows columns that represent 5 minute intervals, but adding up the numbers in all columns, I get around 33K logs in that hour, nowhere near 5 million. &lt;STRONG&gt;This behaviour is consistent, independently of the day or hour I select.&lt;/STRONG&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Q1: Is this some kind of visual bug, or am I interpreting these results in the wrong way?&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Q2: &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;On another note, its visible on the previous photos that all logs are relative to the Product Family&amp;nbsp;&lt;STRONG&gt;Quantum&lt;/STRONG&gt; and Cloud Service&amp;nbsp;&lt;STRONG&gt;Quantum Smart-1 Cloud&lt;/STRONG&gt;, which is to be expected with the current deployment.&lt;/P&gt;&lt;P&gt;However, when I go to Quantum Security Management &amp;amp; Smart-1 Cloud - Logs &amp;amp; Events and select Logs and the same time range I see this:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="logs in day on security management.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/27649i1AFE644981FBA1D1/image-size/medium?v=v2&amp;amp;px=400" role="button" title="logs in day on security management.png" alt="logs in day on security management.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Now there's around 223K logs in that hour as opposed to the 5 million in the Infinity Events. As per my understanding the logs should be the same, but even in the scenario where the 5 million was a visual bug, it still wouldn't make sense because for the time period 9/9/2024 12:00 AM to 9/10/2024 01:00 AM, in the Security Management Logs it says 223K logs and in Infinity Events it says 33K.&lt;/P&gt;&lt;P&gt;I download 10K lines (maximum allowed) of the logs in both the Infinity Events and in Security Management, and after looking at a couple of random lines they seem to contain the same information (unfortunately that doesn't mean much because the 10K lines only contained logs regarding 3 seconds of that whole hour, because of the large amount of logs, so I can't say for sure that the rest of the logs would match)&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Q2: If all the logs I have are generated by Quantum Security Management, why are the quantities of logs in Infinity Events and Quantum Security Management different?&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Sep 2024 08:29:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Events/Mismatch-in-Infinity-Portal-s-Infinity-Event-logs/m-p/226804#M42</guid>
      <dc:creator>RafaelSantiago</dc:creator>
      <dc:date>2024-09-17T08:29:26Z</dc:date>
    </item>
    <item>
      <title>Re: Mismatch in Infinity Portal's Infinity Event logs</title>
      <link>https://community.checkpoint.com/t5/Events/Mismatch-in-Infinity-Portal-s-Infinity-Event-logs/m-p/226830#M43</link>
      <description>&lt;P&gt;"&lt;SPAN&gt;9/9/2024 12:00 AM to 9/10/2024 01:00 AM it says it has around 5 million logs" represents a 25 hour timeframe versus a 1 hour timeframe.&lt;BR /&gt;That might explain why these numbers are so far off.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Sep 2024 16:56:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Events/Mismatch-in-Infinity-Portal-s-Infinity-Event-logs/m-p/226830#M43</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-09-16T16:56:32Z</dc:date>
    </item>
    <item>
      <title>Re: Mismatch in Infinity Portal's Infinity Event logs</title>
      <link>https://community.checkpoint.com/t5/Events/Mismatch-in-Infinity-Portal-s-Infinity-Event-logs/m-p/226886#M44</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;, thank you for the reply. It was my mistake. I meant to say&amp;nbsp;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN&gt;9/9/2024 12:00 AM to &lt;STRONG&gt;9/9/2024&lt;/STRONG&gt; 01:00 AM it says it has around 5 million logs". I fixed it in the post.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The &lt;STRONG&gt;first column&lt;/STRONG&gt; on the time frame 9/9/2024 12:00 AM to 9/10/2024 12:00 AM represents the &lt;STRONG&gt;amount of logs from 12:00 AM to 01:00 AM (5 430 578)&lt;/STRONG&gt;, however when I click said column I get that Statistics graphs, that has around 33K logs.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Sep 2024 08:29:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Events/Mismatch-in-Infinity-Portal-s-Infinity-Event-logs/m-p/226886#M44</guid>
      <dc:creator>RafaelSantiago</dc:creator>
      <dc:date>2024-09-17T08:29:03Z</dc:date>
    </item>
    <item>
      <title>Re: Mismatch in Infinity Portal's Infinity Event logs</title>
      <link>https://community.checkpoint.com/t5/Events/Mismatch-in-Infinity-Portal-s-Infinity-Event-logs/m-p/227003#M45</link>
      <description>&lt;P&gt;I wonder if "Logs" are being used where "Correlated Events" may be more appropriate.&lt;BR /&gt;If you open an individual log, do you see evidence of that?&lt;BR /&gt;There should be a counter inside the log card that reflects this.&lt;/P&gt;</description>
      <pubDate>Tue, 17 Sep 2024 21:17:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Events/Mismatch-in-Infinity-Portal-s-Infinity-Event-logs/m-p/227003#M45</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-09-17T21:17:06Z</dc:date>
    </item>
  </channel>
</rss>

