<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Similar logs For Identity Awareness in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Similar-logs-For-Identity-Awareness/m-p/199469#M4319</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have searched from qradar and got similar logs as below. The only different item is "sequencenum", is this desired situation?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any advice would be appreciated.&lt;/P&gt;&lt;P&gt;Best&lt;/P&gt;&lt;P&gt;Jasmin&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="python"&gt;LEEF:2.0|Check Point|Identity Awareness|1.0|Log In|devTime=devtime               usrName=xxx   cat=Identity Awareness  action=Log In     ifdir=inbound               logid=logid     loguid={aaa}               origin=ip              originsicname=zzz              sequencenum=6               version=5            auth_method=User Authentication (Active Directory)            auth_status=Successful Login      client_name=Active Directory Query               client_version=R81.10     domain_name=domain_name       endpoint_ip=ip_address              identity_src=AD Query   identity_type=user           snid=sn_id   src=src              src_user_group=src_user_group               src_user_name=xxx

LEEF:2.0|Check Point|Identity Awareness|1.0|Log In|devTime=devtime               usrName=xxx   cat=Identity Awareness  action=Log In     ifdir=inbound               logid=logid     loguid={aaa}               origin=ip              originsicname=zzz              sequencenum=7            version=5            auth_method=User Authentication (Active Directory)            auth_status=Successful Login      client_name=Active Directory Query               client_version=R81.10     domain_name=domain_name       endpoint_ip=ip_address              identity_src=AD Query   identity_type=user           snid=sn_id   src=src              src_user_group=src_user_group               src_user_name=xxx&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 01 Dec 2023 14:40:15 GMT</pubDate>
    <dc:creator>JasminThejojo</dc:creator>
    <dc:date>2023-12-01T14:40:15Z</dc:date>
    <item>
      <title>Similar logs For Identity Awareness</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Similar-logs-For-Identity-Awareness/m-p/199469#M4319</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have searched from qradar and got similar logs as below. The only different item is "sequencenum", is this desired situation?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any advice would be appreciated.&lt;/P&gt;&lt;P&gt;Best&lt;/P&gt;&lt;P&gt;Jasmin&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="python"&gt;LEEF:2.0|Check Point|Identity Awareness|1.0|Log In|devTime=devtime               usrName=xxx   cat=Identity Awareness  action=Log In     ifdir=inbound               logid=logid     loguid={aaa}               origin=ip              originsicname=zzz              sequencenum=6               version=5            auth_method=User Authentication (Active Directory)            auth_status=Successful Login      client_name=Active Directory Query               client_version=R81.10     domain_name=domain_name       endpoint_ip=ip_address              identity_src=AD Query   identity_type=user           snid=sn_id   src=src              src_user_group=src_user_group               src_user_name=xxx

LEEF:2.0|Check Point|Identity Awareness|1.0|Log In|devTime=devtime               usrName=xxx   cat=Identity Awareness  action=Log In     ifdir=inbound               logid=logid     loguid={aaa}               origin=ip              originsicname=zzz              sequencenum=7            version=5            auth_method=User Authentication (Active Directory)            auth_status=Successful Login      client_name=Active Directory Query               client_version=R81.10     domain_name=domain_name       endpoint_ip=ip_address              identity_src=AD Query   identity_type=user           snid=sn_id   src=src              src_user_group=src_user_group               src_user_name=xxx&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Dec 2023 14:40:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Similar-logs-For-Identity-Awareness/m-p/199469#M4319</guid>
      <dc:creator>JasminThejojo</dc:creator>
      <dc:date>2023-12-01T14:40:15Z</dc:date>
    </item>
    <item>
      <title>Re: Similar logs For Identity Awareness</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Similar-logs-For-Identity-Awareness/m-p/199485#M4320</link>
      <description>&lt;P&gt;Is the issue you’re seeing multiple logs for what appears to be the same event?&lt;BR /&gt;How far apart are the logs and how many “duplicates” appear?&lt;/P&gt;
&lt;P&gt;We do send multiple logs via Log Exporter for the same session (every 10 minutes or so).&lt;BR /&gt;This is probably expected behavior.&lt;/P&gt;</description>
      <pubDate>Fri, 01 Dec 2023 15:05:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Similar-logs-For-Identity-Awareness/m-p/199485#M4320</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-12-01T15:05:07Z</dc:date>
    </item>
    <item>
      <title>Re: Similar logs For Identity Awareness</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Similar-logs-For-Identity-Awareness/m-p/199493#M4321</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Thanks for your answer. There are two events for login and logout with the same devtime. (not every 10 minutes)&lt;/P&gt;&lt;P&gt;Best&lt;/P&gt;&lt;P&gt;Jasmin&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Dec 2023 15:39:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Similar-logs-For-Identity-Awareness/m-p/199493#M4321</guid>
      <dc:creator>JasminThejojo</dc:creator>
      <dc:date>2023-12-01T15:39:12Z</dc:date>
    </item>
    <item>
      <title>Re: Similar logs For Identity Awareness</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Similar-logs-For-Identity-Awareness/m-p/199494#M4322</link>
      <description>&lt;P&gt;Two logs for the same event that close to each other doesn't seem correct.&lt;BR /&gt;Best to check this with TAC: &lt;A href="https://help.checkpoint.com" target="_blank"&gt;https://help.checkpoint.com&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Dec 2023 15:42:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Similar-logs-For-Identity-Awareness/m-p/199494#M4322</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-12-01T15:42:11Z</dc:date>
    </item>
  </channel>
</rss>

