<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AI Example in Playblocks</title>
    <link>https://community.checkpoint.com/t5/Playblocks/AI-Example/m-p/247290#M51</link>
    <description>&lt;P class="" data-start="82" data-end="122"&gt;Great point- and you're absolutely right!&lt;/P&gt;
&lt;P class="" data-start="124" data-end="331"&gt;To avoid alert fatigue, we’ve built in several ways to add smart conditions to the &lt;STRONG data-start="207" data-end="222"&gt;Log Trigger&lt;/STRONG&gt; step.&lt;/P&gt;
&lt;P class="" data-start="124" data-end="331"&gt;For example, you can ask the AI to trigger only on &lt;STRONG data-start="280" data-end="303"&gt;consecutive attacks&lt;/STRONG&gt;, or define conditions like:&lt;/P&gt;
&lt;UL&gt;
&lt;LI data-start="409" data-end="453"&gt;&lt;STRONG&gt;Counting logs within a specific time frame&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI data-start="456" data-end="508"&gt;&lt;STRONG&gt;Counting distinct values&lt;/STRONG&gt; (e.g., unique source IPs)&lt;/LI&gt;
&lt;LI class="" data-start="454" data-end="508"&gt;
&lt;P class="" data-start="456" data-end="508"&gt;&lt;STRONG&gt;Suppressing repeated logs&lt;/STRONG&gt; to avoid noise&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P class="" data-start="553" data-end="696"&gt;We’ve also recently added a powerful new condition that lets you filter logs based on &lt;STRONG data-start="639" data-end="658"&gt;IP Geo-location&lt;/STRONG&gt;, using fields directly from the logs.&lt;/P&gt;
&lt;P class="" data-start="698" data-end="764"&gt;I’ve attached a few screenshots below so you can see it in action.&lt;/P&gt;
&lt;P class="" data-start="766" data-end="954"&gt;And regarding newly created AI automations, users can review, re-generate, and fully edit the automation at any time before enabling it.&amp;nbsp;&lt;/P&gt;
&lt;P class="" data-start="779" data-end="841"&gt;Thanks again for raising this - it's an important consideration!&lt;/P&gt;
&lt;DIV id="tinyMceEditor_545d1a2c5904caTal_Ben_Bassat_0" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Count logs - distinct" style="width: 562px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/30319i84E8460788E54109/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="Count logs - distinct" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Count logs - distinct&lt;/span&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Suppress logs" style="width: 553px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/30320i467EF7AA2870C2F4/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="Suppress logs" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Suppress logs&lt;/span&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Count logs - occurrences by field" style="width: 547px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/30321iE9882648EE81E9C5/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="Count logs - occurrences by field" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Count logs - occurrences by field&lt;/span&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="IP Geolocation - included/ excluded from specific countries" style="width: 554px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/30322i2C3A1455C748237D/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="IP Geolocation - included/ excluded from specific countries" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;IP Geolocation - included/ excluded from specific countries&lt;/span&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Many options for conditions on logs" style="width: 533px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/30323i3F52DFA53A27900D/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="Many options for conditions on logs" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Many options for conditions on logs&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 25 Apr 2025 07:03:18 GMT</pubDate>
    <dc:creator>Tal_Ben_Bassat</dc:creator>
    <dc:date>2025-04-25T07:03:18Z</dc:date>
    <item>
      <title>AI Example</title>
      <link>https://community.checkpoint.com/t5/Playblocks/AI-Example/m-p/247136#M50</link>
      <description>&lt;P&gt;Very interesting idea. I think in your example you are going to need additional checks or the notifications are going to get out of hand. Imagine an IPS attack coming from a block range of IP's, or even revolving IP's in the case of a botnet and receiving a notification for every hit. Probably also need the ability to do a sanity check and approve any newly created AI rule.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Apr 2025 15:26:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Playblocks/AI-Example/m-p/247136#M50</guid>
      <dc:creator>Tony_Graham</dc:creator>
      <dc:date>2025-04-23T15:26:26Z</dc:date>
    </item>
    <item>
      <title>Re: AI Example</title>
      <link>https://community.checkpoint.com/t5/Playblocks/AI-Example/m-p/247290#M51</link>
      <description>&lt;P class="" data-start="82" data-end="122"&gt;Great point- and you're absolutely right!&lt;/P&gt;
&lt;P class="" data-start="124" data-end="331"&gt;To avoid alert fatigue, we’ve built in several ways to add smart conditions to the &lt;STRONG data-start="207" data-end="222"&gt;Log Trigger&lt;/STRONG&gt; step.&lt;/P&gt;
&lt;P class="" data-start="124" data-end="331"&gt;For example, you can ask the AI to trigger only on &lt;STRONG data-start="280" data-end="303"&gt;consecutive attacks&lt;/STRONG&gt;, or define conditions like:&lt;/P&gt;
&lt;UL&gt;
&lt;LI data-start="409" data-end="453"&gt;&lt;STRONG&gt;Counting logs within a specific time frame&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI data-start="456" data-end="508"&gt;&lt;STRONG&gt;Counting distinct values&lt;/STRONG&gt; (e.g., unique source IPs)&lt;/LI&gt;
&lt;LI class="" data-start="454" data-end="508"&gt;
&lt;P class="" data-start="456" data-end="508"&gt;&lt;STRONG&gt;Suppressing repeated logs&lt;/STRONG&gt; to avoid noise&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P class="" data-start="553" data-end="696"&gt;We’ve also recently added a powerful new condition that lets you filter logs based on &lt;STRONG data-start="639" data-end="658"&gt;IP Geo-location&lt;/STRONG&gt;, using fields directly from the logs.&lt;/P&gt;
&lt;P class="" data-start="698" data-end="764"&gt;I’ve attached a few screenshots below so you can see it in action.&lt;/P&gt;
&lt;P class="" data-start="766" data-end="954"&gt;And regarding newly created AI automations, users can review, re-generate, and fully edit the automation at any time before enabling it.&amp;nbsp;&lt;/P&gt;
&lt;P class="" data-start="779" data-end="841"&gt;Thanks again for raising this - it's an important consideration!&lt;/P&gt;
&lt;DIV id="tinyMceEditor_545d1a2c5904caTal_Ben_Bassat_0" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Count logs - distinct" style="width: 562px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/30319i84E8460788E54109/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="Count logs - distinct" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Count logs - distinct&lt;/span&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Suppress logs" style="width: 553px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/30320i467EF7AA2870C2F4/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="Suppress logs" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Suppress logs&lt;/span&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Count logs - occurrences by field" style="width: 547px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/30321iE9882648EE81E9C5/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="Count logs - occurrences by field" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Count logs - occurrences by field&lt;/span&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="IP Geolocation - included/ excluded from specific countries" style="width: 554px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/30322i2C3A1455C748237D/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="IP Geolocation - included/ excluded from specific countries" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;IP Geolocation - included/ excluded from specific countries&lt;/span&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Many options for conditions on logs" style="width: 533px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/30323i3F52DFA53A27900D/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="Many options for conditions on logs" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Many options for conditions on logs&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Apr 2025 07:03:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Playblocks/AI-Example/m-p/247290#M51</guid>
      <dc:creator>Tal_Ben_Bassat</dc:creator>
      <dc:date>2025-04-25T07:03:18Z</dc:date>
    </item>
  </channel>
</rss>

