<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Sending syslog from SMB - application fields are blank in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Sending-syslog-from-SMB-application-fields-are-blank/m-p/34509#M1433</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #000000;"&gt;show application-control-engine-settings advanced-settings&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000;"&gt;could give you a clou but I could not find it, but this could still be something controlled from the dashboard as the box is managed. In the OPSec it is called Log Permissions.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 26 Jun 2018 21:52:01 GMT</pubDate>
    <dc:creator>Maarten_Sjouw</dc:creator>
    <dc:date>2018-06-26T21:52:01Z</dc:date>
    <item>
      <title>Sending syslog from SMB - application fields are blank</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Sending-syslog-from-SMB-application-fields-are-blank/m-p/34506#M1430</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am sending security logs from a 1490 via syslog to an external log server, but Application Control and URL Filtering fields show as "******":&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #2d2d2d; background-color: #ffffff;"&gt;appi_name="******" app_desc="******" app_id="******" app_category="******" matched_category="******" app_properties="******" app_risk="******" app_rule_id="******" app_rule_name="******"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #2d2d2d; background-color: #ffffff;"&gt;Is this a limitation or is it because of some kind of privacy setting?&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Jun 2018 17:40:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Sending-syslog-from-SMB-application-fields-are-blank/m-p/34506#M1430</guid>
      <dc:creator>Pedro_Espindola</dc:creator>
      <dc:date>2018-06-26T17:40:54Z</dc:date>
    </item>
    <item>
      <title>Re: Sending syslog from SMB - application fields are blank</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Sending-syslog-from-SMB-application-fields-are-blank/m-p/34507#M1431</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I know this is a setting in the OPSec connection, but I have not been able to find anything on the 1400 WEBUI to set anything in this area. I was also browsing through the CLI guide and there is some stuff about the user awareness, which brought the following question to mind; does you log show the user and URL information, or is that obfuscated as well?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the other hand when this is an centrally managed gateway you could use the log exporter instead from management, this will give you much more control over what is sent to the syslog server.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Jun 2018 18:22:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Sending-syslog-from-SMB-application-fields-are-blank/m-p/34507#M1431</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2018-06-26T18:22:17Z</dc:date>
    </item>
    <item>
      <title>Re: Sending syslog from SMB - application fields are blank</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Sending-syslog-from-SMB-application-fields-are-blank/m-p/34508#M1432</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Actually, users are shown correctly. Only the fields related to the application are hidden. Check this log from my lab:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #2d2d2d; background-color: #ffffff;"&gt;&amp;lt;85&amp;gt;2018-06-26T17:44:09.562830-03:00 Jun 26 17:44:07--3:00 192.168.252.1 Action="allow" UUid="{0x5b32a597,0x6,0x52c2737f,0xc0000002}" src="172.20.120.50" dst="216.58.222.78" proto="17" appi_name="******" app_desc="******" app_id="******" app_category="******" matched_category="******" app_properties="******" app_risk="******" app_rule_id="******" app_rule_name="******" app_sig_id="60340654:4" proxy_src_ip="172.20.120.50" user="Administrator(+)" src_user_name="Administrator(+)" snid="d671fcfa" product="Application Control" service="443" s_port="56644"&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Jun 2018 20:47:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Sending-syslog-from-SMB-application-fields-are-blank/m-p/34508#M1432</guid>
      <dc:creator>Pedro_Espindola</dc:creator>
      <dc:date>2018-06-26T20:47:57Z</dc:date>
    </item>
    <item>
      <title>Re: Sending syslog from SMB - application fields are blank</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Sending-syslog-from-SMB-application-fields-are-blank/m-p/34509#M1433</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #000000;"&gt;show application-control-engine-settings advanced-settings&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000;"&gt;could give you a clou but I could not find it, but this could still be something controlled from the dashboard as the box is managed. In the OPSec it is called Log Permissions.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Jun 2018 21:52:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Sending-syslog-from-SMB-application-fields-are-blank/m-p/34509#M1433</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2018-06-26T21:52:01Z</dc:date>
    </item>
    <item>
      <title>Re: Sending syslog from SMB - application fields are blank</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Sending-syslog-from-SMB-application-fields-are-blank/m-p/34510#M1434</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #000000;"&gt;show application-control-engine-settings advanced-settings&lt;/SPAN&gt; does not exist in my Firmware &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What i know this issue from is &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk73400&amp;amp;partition=Advanced&amp;amp;product=SmartLog%22"&gt;&lt;EM&gt;sk73400 SmartLog displays some fields with asterisks in logs from Application Control blade or from Identity Awareness blade&lt;/EM&gt;&lt;/A&gt;.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Jul 2018 14:42:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Sending-syslog-from-SMB-application-fields-are-blank/m-p/34510#M1434</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2018-07-02T14:42:13Z</dc:date>
    </item>
    <item>
      <title>Re: Sending syslog from SMB - application fields are blank</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Sending-syslog-from-SMB-application-fields-are-blank/m-p/34511#M1435</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;from the&amp;nbsp; 700-1400 appliances R77.20.75 Techincal Reference Guide:&lt;/P&gt;&lt;TABLE border="0" cellpadding="5" style="color: #000000; font-size: 10pt;" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;A href="https://sc1.checkpoint.com/documents/R77.20.75/R77.20.75_600_700_1100_1200R_1400_CLI_Guide/165248.htm#o168634" style="color: #0026ff;" target="BODY"&gt;set&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;application-control-engine&lt;/STRONG&gt;-settings&lt;/A&gt;&lt;BR /&gt;set&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;application-control-engine&lt;/STRONG&gt;-settings advanced-settings fail-mode &amp;lt;fail-mode&amp;gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;A href="https://sc1.checkpoint.com/documents/R77.20.75/R77.20.75_600_700_1100_1200R_1400_CLI_Guide/165248.htm#o168646" style="color: #0026ff;" target="BODY"&gt;set&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;application-control-engine&lt;/STRONG&gt;-settings&lt;/A&gt;&lt;BR /&gt;set&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;application-control-engine&lt;/STRONG&gt;-settings advanced-settings&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;A href="https://sc1.checkpoint.com/documents/R77.20.75/R77.20.75_600_700_1100_1200R_1400_CLI_Guide/165248.htm#o168657" style="color: #0026ff;" target="BODY"&gt;set&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;application-control-engine&lt;/STRONG&gt;-settings&lt;/A&gt;&lt;BR /&gt;set&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;application-control-engine&lt;/STRONG&gt;-settings advanced-settings enforce-safe-search &amp;lt;enforce-safe-search&amp;gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;A href="https://sc1.checkpoint.com/documents/R77.20.75/R77.20.75_600_700_1100_1200R_1400_CLI_Guide/165248.htm#o168669" style="color: #0026ff;" target="BODY"&gt;set&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;application-control-engine&lt;/STRONG&gt;-settings&lt;/A&gt;&lt;BR /&gt;set&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;application-control-engine&lt;/STRONG&gt;-settings advanced-settings web-site-categorization-mode &amp;lt;web-site-categorization-mode&amp;gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;A href="https://sc1.checkpoint.com/documents/R77.20.75/R77.20.75_600_700_1100_1200R_1400_CLI_Guide/165248.htm#o168680" style="color: #0026ff;" target="BODY"&gt;set&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;application-control-engine&lt;/STRONG&gt;-settings&lt;/A&gt;&lt;BR /&gt;set&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;application-control-engine&lt;/STRONG&gt;-settings advanced-settings track-browse-time&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;A href="https://sc1.checkpoint.com/documents/R77.20.75/R77.20.75_600_700_1100_1200R_1400_CLI_Guide/165248.htm#o168692" style="color: #0026ff;" target="BODY"&gt;set&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;application-control-engine&lt;/STRONG&gt;-settings&lt;/A&gt;&lt;BR /&gt;set&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;application-control-engine&lt;/STRONG&gt;-settings advanced-settings http-referrer-identification &amp;lt;http-referrer-identification&amp;gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;A href="https://sc1.checkpoint.com/documents/R77.20.75/R77.20.75_600_700_1100_1200R_1400_CLI_Guide/165248.htm#o168702" style="color: #0026ff;" target="BODY"&gt;set&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;application-control-engine&lt;/STRONG&gt;-settings&lt;/A&gt;&lt;BR /&gt;set&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;application-control-engine&lt;/STRONG&gt;-settings advanced-settings&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;A href="https://sc1.checkpoint.com/documents/R77.20.75/R77.20.75_600_700_1100_1200R_1400_CLI_Guide/165248.htm#o165553" style="color: #0026ff;" target="BODY"&gt;show&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;application-control-engine&lt;/STRONG&gt;-settings&lt;/A&gt;&lt;BR /&gt;show&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;application-control-engine&lt;/STRONG&gt;-settings advanced-settings&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P class="" style="color: #000000; font-weight: bold; font-size: 10pt;"&gt;&amp;nbsp;9 result(s) found.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Jul 2018 21:29:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Sending-syslog-from-SMB-application-fields-are-blank/m-p/34511#M1435</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2018-07-02T21:29:25Z</dc:date>
    </item>
    <item>
      <title>Re: Sending syslog from SMB - application fields are blank</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Sending-syslog-from-SMB-application-fields-are-blank/m-p/34512#M1436</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It is found in&amp;nbsp;Check Point 600/700/1100/1200R/1400 Appliance Guide R77.20.75 p.96 - but in clish, it is not a shown command, that was the reason for my remark &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Jul 2018 06:52:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Sending-syslog-from-SMB-application-fields-are-blank/m-p/34512#M1436</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2018-07-03T06:52:51Z</dc:date>
    </item>
    <item>
      <title>Re: Sending syslog from SMB - application fields are blank</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Sending-syslog-from-SMB-application-fields-are-blank/m-p/34513#M1437</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The support team said this is a limitation, the same as described in&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk112376&amp;amp;partition=Advanced&amp;amp;product=Security"&gt;sk112376 - Logs appear as confidential when configuring a Security Gateway R77.30 Gaia to send logs to an external Syslog server&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will submit a request for enhancement. If&amp;nbsp;&lt;A href="https://community.checkpoint.com/migrated-users/50921"&gt;Maarten Sjouw&lt;/A&gt;&amp;nbsp;and the others could do the same I would be grateful.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for the help, guys.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Jul 2018 17:30:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Sending-syslog-from-SMB-application-fields-are-blank/m-p/34513#M1437</guid>
      <dc:creator>Pedro_Espindola</dc:creator>
      <dc:date>2018-07-17T17:30:09Z</dc:date>
    </item>
    <item>
      <title>Re: Sending syslog from SMB - application fields are blank</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Sending-syslog-from-SMB-application-fields-are-blank/m-p/34514#M1438</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It seems on version R77.20.81 the problem was solved with an option to show these fields:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Show Obfuscated Fields" class="image-1 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/74999_ObfuscatedFields.PNG" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sometimes RFEs work!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Nov 2018 22:09:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Sending-syslog-from-SMB-application-fields-are-blank/m-p/34514#M1438</guid>
      <dc:creator>Pedro_Espindola</dc:creator>
      <dc:date>2018-11-23T22:09:53Z</dc:date>
    </item>
  </channel>
</rss>

