<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 1550 - Syslog Server - Where's the &amp;quot;Action&amp;quot;? in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1550-Syslog-Server-Where-s-the-quot-Action-quot/m-p/73828#M2917</link>
    <description>&lt;P&gt;Also this is a locally managed firewall.&lt;/P&gt;</description>
    <pubDate>Fri, 31 Jan 2020 00:16:28 GMT</pubDate>
    <dc:creator>Max_Baumgarten</dc:creator>
    <dc:date>2020-01-31T00:16:28Z</dc:date>
    <item>
      <title>1550 - Syslog Server - Where's the "Action"?</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1550-Syslog-Server-Where-s-the-quot-Action-quot/m-p/73790#M2910</link>
      <description>&lt;P&gt;Hey All,&lt;BR /&gt;&lt;BR /&gt;I'm currently using a checkpoint 1550 configured to send System and Security logs to a simple Ubuntu server running rsyslog.&lt;BR /&gt;&lt;BR /&gt;Going through the logs on the Ubuntu server, it seems like the 1550 is not sending any "Action" information for any of the logs, whether its Drop or Accept.&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;Simple Ping that should be Dropped:&lt;/STRONG&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;Jan 30 11:16:14 Jan 30 11:16:11--5:00 
10.x.x.x
inzone="External" 
outzone="Local" 
service_id="ICMP" 
ICMP="Echo Request" 
src="207.xxx.xxx.xxx" 
dst="128.xxx.xxx.xxx" 
proto="1" 
ICMP Type="8" 
ICMP Code="0" 
user="" 
src_user_name="" 
src_machine_name="" 
src_user_dn=""
snid="" 
dst_user_name="" 
dst_machine_name="" 
dst_user_dn="" 
UP_match_table="TABLE_START" 
ROW_START="0" 
match_id="5" 
layer_uuid="9fced3b3-5da9-494d-b7f1-3242694d99f8" 
layer_name="internal" 
rule_uid="00000780-0000-0000-0000-000000000000" 
rule_name="Incoming/Internal Default Policy"
ROW_END="0"
UP_match_table="TABLE_END" 
ProductName="VPN-1 &amp;amp; FireWall-1" 
ProductFamily=""&lt;/LI-CODE&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;Simple Ping that should be Accepted:&lt;/STRONG&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;Jan 30 11:24:34 Jan 30 11:24:33--5:00
10.x.x.x 
inzone="Internal" 
outzone="Local" 
service_id="ICMP" 
ICMP="Echo Request" 
src="10.x.x.x" 
dst="10.x.x.x" 
proto="1" 
ICMP Type="8"
ICMP Code="0" 
user="" 
src_user_name=""
src_machine_name=""
src_user_dn=""
snid=""
dst_user_name=""
dst_machine_name=""
dst_user_dn=""
UP_match_table="TABLE_START"
ROW_START="0"
match_id="5"
layer_uuid="9fced3b3-5da9-494d-b7f1-3242694d99f8" 
layer_name="internal"
rule_uid="00000780-0000-0000-0000-000000000000"
rule_name="Incoming/Internal Default Policy"
ROW_END="0" 
UP_match_table="TABLE_END"
ProductName="VPN-1 &amp;amp; FireWall-1"
ProductFamily=""&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Am I missing something here? Shouldn't there be a field for "Action="?&amp;nbsp; Perhaps my syslog server has a formatting issue?&amp;nbsp; Others have told me they can't find the Action field either when looking at syslog files for their 1550.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;I plan on using these logs in an Elastic Stack, but without having Action in the logs, it makes the data extremely difficult (and possibly pointless) to use.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jan 2020 17:01:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1550-Syslog-Server-Where-s-the-quot-Action-quot/m-p/73790#M2910</guid>
      <dc:creator>Max_Baumgarten</dc:creator>
      <dc:date>2020-01-30T17:01:10Z</dc:date>
    </item>
    <item>
      <title>Re: 1550 - Syslog Server - Where's the "Action"?</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1550-Syslog-Server-Where-s-the-quot-Action-quot/m-p/73828#M2917</link>
      <description>&lt;P&gt;Also this is a locally managed firewall.&lt;/P&gt;</description>
      <pubDate>Fri, 31 Jan 2020 00:16:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1550-Syslog-Server-Where-s-the-quot-Action-quot/m-p/73828#M2917</guid>
      <dc:creator>Max_Baumgarten</dc:creator>
      <dc:date>2020-01-31T00:16:28Z</dc:date>
    </item>
    <item>
      <title>Re: 1550 - Syslog Server - Where's the "Action"?</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1550-Syslog-Server-Where-s-the-quot-Action-quot/m-p/73907#M2920</link>
      <description>Might be worth a TAC case to investigate if this is expected behavior or not.</description>
      <pubDate>Sat, 01 Feb 2020 00:19:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1550-Syslog-Server-Where-s-the-quot-Action-quot/m-p/73907#M2920</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-02-01T00:19:03Z</dc:date>
    </item>
    <item>
      <title>Re: 1550 - Syslog Server - Where's the "Action"?</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1550-Syslog-Server-Where-s-the-quot-Action-quot/m-p/74107#M2930</link>
      <description>&lt;P&gt;Is the Action shown if you look at the log entry in WebGUI logs ?&lt;/P&gt;</description>
      <pubDate>Tue, 04 Feb 2020 12:28:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1550-Syslog-Server-Where-s-the-quot-Action-quot/m-p/74107#M2930</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2020-02-04T12:28:19Z</dc:date>
    </item>
    <item>
      <title>Re: 1550 - Syslog Server - Where's the "Action"?</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1550-Syslog-Server-Where-s-the-quot-Action-quot/m-p/74113#M2931</link>
      <description>&lt;P&gt;The action is shown perfectly fine in the GUI.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Feb 2020 13:07:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1550-Syslog-Server-Where-s-the-quot-Action-quot/m-p/74113#M2931</guid>
      <dc:creator>Max_Baumgarten</dc:creator>
      <dc:date>2020-02-04T13:07:56Z</dc:date>
    </item>
  </channel>
</rss>

