<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Useless logs in SMB appliances in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Useless-logs-in-SMB-appliances/m-p/48758#M1891</link>
    <description>Can you find the relevant log entries via the Protection Name (which should be unique enough)?</description>
    <pubDate>Tue, 26 Mar 2019 21:39:05 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2019-03-26T21:39:05Z</dc:date>
    <item>
      <title>Useless logs in SMB appliances</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Useless-logs-in-SMB-appliances/m-p/48550#M1882</link>
      <description>&lt;P&gt;Can someone explain what actionable information is available in this log entry:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/405i5586FA71C97DDF4E/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Except an acknowledgement that the gateway recognized malicious binary but was not able to prevent its download?&lt;/P&gt;
&lt;P&gt;There is no way I can see that allow us to identify the binary from the information displayed.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Mar 2019 00:14:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Useless-logs-in-SMB-appliances/m-p/48550#M1882</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2019-03-26T00:14:41Z</dc:date>
    </item>
    <item>
      <title>Re: Useless logs in SMB appliances</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Useless-logs-in-SMB-appliances/m-p/48553#M1883</link>
      <description>It doesn't list a URL, site, or anything? What do other logs around that time for that host say?</description>
      <pubDate>Tue, 26 Mar 2019 01:54:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Useless-logs-in-SMB-appliances/m-p/48553#M1883</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-03-26T01:54:56Z</dc:date>
    </item>
    <item>
      <title>Re: Useless logs in SMB appliances</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Useless-logs-in-SMB-appliances/m-p/48654#M1886</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;, If you look closely at the log shown, you'll see that it only shows date, not time of the incident. We have only option to "View Host Logs" from the "Infected Hosts" section.&lt;/P&gt;
&lt;P&gt;This opens up logs filtered by the host's IP with the current date and time.&lt;/P&gt;
&lt;P&gt;The SMB appliances log query does not permit multiple filters, but only one:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 688px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/426i938DEBCF1C449283/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So we have to either scroll back to the date and look at ALL THE LOGS for that host or filter by the host and look for ALL THE LOGS for that date.&lt;/P&gt;
&lt;P&gt;What do you think the likelihood of finding what we are looking for?&lt;/P&gt;</description>
      <pubDate>Tue, 26 Mar 2019 13:00:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Useless-logs-in-SMB-appliances/m-p/48654#M1886</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2019-03-26T13:00:13Z</dc:date>
    </item>
    <item>
      <title>Re: Useless logs in SMB appliances</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Useless-logs-in-SMB-appliances/m-p/48758#M1891</link>
      <description>Can you find the relevant log entries via the Protection Name (which should be unique enough)?</description>
      <pubDate>Tue, 26 Mar 2019 21:39:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Useless-logs-in-SMB-appliances/m-p/48758#M1891</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-03-26T21:39:05Z</dc:date>
    </item>
    <item>
      <title>Re: Useless logs in SMB appliances</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Useless-logs-in-SMB-appliances/m-p/48770#M1892</link>
      <description>&lt;P&gt;Found it using the method you suggested.&lt;/P&gt;
&lt;P&gt;Few notes though:&lt;/P&gt;
&lt;P&gt;1. Would be nice if the "Open Host Logs" from TP would go to the event, not to current logs.&lt;/P&gt;
&lt;P&gt;2. Actual event log indicated that the download was prevented, while TP notice indicates "Possible Infected Host."&lt;/P&gt;
&lt;P&gt;3. There is no export or copy option for the events for reporting to the offending party.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Mar 2019 23:47:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Useless-logs-in-SMB-appliances/m-p/48770#M1892</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2019-03-26T23:47:02Z</dc:date>
    </item>
  </channel>
</rss>

