<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SMB syslog doesn't log action in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-syslog-doesn-t-log-action/m-p/74256#M2953</link>
    <description>&lt;P&gt;We've confirmed it does not work in r80.xx, but used to work in r77.&amp;nbsp; For some unknown reason, this was removed and apparently there are no plans to ever add it back.&lt;/P&gt;</description>
    <pubDate>Wed, 05 Feb 2020 17:53:47 GMT</pubDate>
    <dc:creator>Max_Baumgarten</dc:creator>
    <dc:date>2020-02-05T17:53:47Z</dc:date>
    <item>
      <title>SMB syslog doesn't log action</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-syslog-doesn-t-log-action/m-p/74126#M2932</link>
      <description>&lt;P&gt;So I'm rather shocked by this but I've just learned syslog from a SMB (and possibly none SMB as well) will not log the action field to syslog. I was pointed to&amp;nbsp;&lt;SPAN&gt;sk164514 which I can't seem to access. Not sure if this is internal or not.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I don't even know what to say about this. I have a firewall that isn't logging via syslog if anything is accepted&amp;nbsp;or denied. Its just saying.. stuff happened... I'm going to take a stab at a log exporter but I have no idea if thats possible without a management server. This is @%^$@#% ridiculous.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I sure am glad all these items below are getting logged instead of action. I don't know what I would do without knowing where the start or end of the table is (or what that even means). Good to know that the snid is unknown.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Awesome.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;user="" 
src_user_name="" 
src_machine_name="" 
src_user_dn=""
snid="" 
dst_user_name="" 
dst_machine_name="" 
dst_user_dn="" 
UP_match_table="TABLE_START" 
ROW_START="0" 
match_id="5" 
layer_uuid="9fced3b3-5da9-494d-b7f1-3242694d99f8" 
layer_name="internal" 
rule_uid="00000780-0000-0000-0000-000000000000" 
rule_name="Incoming/Internal Default Policy"
ROW_END="0"
UP_match_table="TABLE_END" &lt;/PRE&gt;&lt;P&gt;&amp;nbsp;I&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Feb 2020 15:36:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-syslog-doesn-t-log-action/m-p/74126#M2932</guid>
      <dc:creator>John_Fleming</dc:creator>
      <dc:date>2020-02-04T15:36:35Z</dc:date>
    </item>
    <item>
      <title>Re: SMB syslog doesn't log action</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-syslog-doesn-t-log-action/m-p/74128#M2933</link>
      <description>&lt;P&gt;Wow. Glad to see its not just me (&lt;A href="https://community.checkpoint.com/t5/SMB-Appliances-and-SMP/1550-Syslog-Server-Where-s-the-quot-Action-quot/m-p/73790#M2910" target="_blank" rel="noopener"&gt;my post&lt;/A&gt;) .&amp;nbsp; Seems almost &lt;STRONG&gt;inexcusable&lt;/STRONG&gt; to have syslogs for a firewall and not have it report the Action.&amp;nbsp; &amp;nbsp;These logs are completely useless for customers who want to use these logs for any analysis.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Feb 2020 15:43:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-syslog-doesn-t-log-action/m-p/74128#M2933</guid>
      <dc:creator>Max_Baumgarten</dc:creator>
      <dc:date>2020-02-04T15:43:10Z</dc:date>
    </item>
    <item>
      <title>Re: SMB syslog doesn't log action</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-syslog-doesn-t-log-action/m-p/74132#M2935</link>
      <description>&lt;P&gt;Which firewalls you know of do send their security logs including Accept / Deny / Reject actions using syslog ?&lt;/P&gt;</description>
      <pubDate>Tue, 04 Feb 2020 16:16:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-syslog-doesn-t-log-action/m-p/74132#M2935</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2020-02-04T16:16:41Z</dc:date>
    </item>
    <item>
      <title>Re: SMB syslog doesn't log action</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-syslog-doesn-t-log-action/m-p/74133#M2936</link>
      <description>&lt;P&gt;Of other vendors: Fortinet, PfSense, Ubiquti Edgerouters...&amp;nbsp; Pretty sure Cisco ASAs and Palo Altos do this as well.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Feb 2020 16:26:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-syslog-doesn-t-log-action/m-p/74133#M2936</guid>
      <dc:creator>Max_Baumgarten</dc:creator>
      <dc:date>2020-02-04T16:26:04Z</dc:date>
    </item>
    <item>
      <title>Re: SMB syslog doesn't log action</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-syslog-doesn-t-log-action/m-p/74136#M2937</link>
      <description>&lt;P&gt;Come on, take it easy. This is apparently some negligence from our lovely vendor. Open SR and they will fix it right away!&lt;/P&gt;</description>
      <pubDate>Tue, 04 Feb 2020 16:41:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-syslog-doesn-t-log-action/m-p/74136#M2937</guid>
      <dc:creator>HristoGrigorov</dc:creator>
      <dc:date>2020-02-04T16:41:51Z</dc:date>
    </item>
    <item>
      <title>Re: SMB syslog doesn't log action</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-syslog-doesn-t-log-action/m-p/74141#M2938</link>
      <description>&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":rolling_on_the_floor_laughing:"&gt;🤣&lt;/span&gt;&lt;span class="lia-unicode-emoji" title=":rolling_on_the_floor_laughing:"&gt;🤣&lt;/span&gt;&lt;span class="lia-unicode-emoji" title=":rolling_on_the_floor_laughing:"&gt;🤣&lt;/span&gt;&lt;span class="lia-unicode-emoji" title=":rolling_on_the_floor_laughing:"&gt;🤣&lt;/span&gt;&lt;span class="lia-unicode-emoji" title=":rolling_on_the_floor_laughing:"&gt;🤣&lt;/span&gt;&lt;span class="lia-unicode-emoji" title=":rolling_on_the_floor_laughing:"&gt;🤣&lt;/span&gt;&lt;span class="lia-unicode-emoji" title=":rolling_on_the_floor_laughing:"&gt;🤣&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Feb 2020 17:44:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-syslog-doesn-t-log-action/m-p/74141#M2938</guid>
      <dc:creator>Max_Baumgarten</dc:creator>
      <dc:date>2020-02-04T17:44:49Z</dc:date>
    </item>
    <item>
      <title>Re: SMB syslog doesn't log action</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-syslog-doesn-t-log-action/m-p/74144#M2940</link>
      <description>&lt;P&gt;Yeah, I did open a ticket. The reply was R&amp;amp;D will not be fixing this, its a known issue and i'll need to submit a RFE.&lt;/P&gt;&lt;P&gt;Also I can't use log exporter because there is no mgmt server involved (this is local mgmt).&lt;/P&gt;</description>
      <pubDate>Tue, 04 Feb 2020 18:16:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-syslog-doesn-t-log-action/m-p/74144#M2940</guid>
      <dc:creator>John_Fleming</dc:creator>
      <dc:date>2020-02-04T18:16:56Z</dc:date>
    </item>
    <item>
      <title>Re: SMB syslog doesn't log action</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-syslog-doesn-t-log-action/m-p/74146#M2942</link>
      <description>&lt;P&gt;yeah that's a bit strange (to say which do log action). It would make more sense to say of the ones that do send syslog which "don't" indicate what the action was. I mean I can't see why the action would be more or less valuable then the source / destination if the concern was somehow information leakage. As it stands I see no way to get logs off a local manged SMB that are of any use.&lt;/P&gt;&lt;P&gt;Its like I need to pay a management server tax to have external logs. I mean the webui is basically useless for any in depth research since the query language only supports a single element. (src, dst, product etc).&lt;/P&gt;</description>
      <pubDate>Tue, 04 Feb 2020 18:28:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-syslog-doesn-t-log-action/m-p/74146#M2942</guid>
      <dc:creator>John_Fleming</dc:creator>
      <dc:date>2020-02-04T18:28:24Z</dc:date>
    </item>
    <item>
      <title>Re: SMB syslog doesn't log action</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-syslog-doesn-t-log-action/m-p/74148#M2943</link>
      <description>&lt;P&gt;I do not remember quite well but I think in R77.20 GE there is action field in syslog records.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Feb 2020 18:33:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-syslog-doesn-t-log-action/m-p/74148#M2943</guid>
      <dc:creator>HristoGrigorov</dc:creator>
      <dc:date>2020-02-04T18:33:16Z</dc:date>
    </item>
    <item>
      <title>Re: SMB syslog doesn't log action</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-syslog-doesn-t-log-action/m-p/74161#M2947</link>
      <description>&lt;P&gt;You are %100 correct. Just tested R77.30 open server.&lt;/P&gt;&lt;P&gt;Syslog logs accept and drop messages.&lt;/P&gt;&lt;P&gt;R80.20 open server. Not it doesn't, yes we know, we're not fixing it, go get RFEed.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Feb 2020 22:23:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-syslog-doesn-t-log-action/m-p/74161#M2947</guid>
      <dc:creator>John_Fleming</dc:creator>
      <dc:date>2020-02-04T22:23:05Z</dc:date>
    </item>
    <item>
      <title>Re: SMB syslog doesn't log action</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-syslog-doesn-t-log-action/m-p/74162#M2948</link>
      <description>&lt;P&gt;Obviously, you don't need that syslog information to protect against &lt;STRONG&gt;&lt;FONT color="#FF00FF"&gt;GEN 6&lt;/FONT&gt;&lt;/STRONG&gt;&amp;nbsp;attacks....&lt;/P&gt;</description>
      <pubDate>Tue, 04 Feb 2020 22:46:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-syslog-doesn-t-log-action/m-p/74162#M2948</guid>
      <dc:creator>Max_Baumgarten</dc:creator>
      <dc:date>2020-02-04T22:46:32Z</dc:date>
    </item>
    <item>
      <title>Re: SMB syslog doesn't log action</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-syslog-doesn-t-log-action/m-p/74168#M2949</link>
      <description>&lt;P&gt;There must be a technical explanation as to why it was dropped. May be because of the layered policy... I hope R&amp;amp;D is monitoring this thread and will provide some details about this.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Feb 2020 04:22:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-syslog-doesn-t-log-action/m-p/74168#M2949</guid>
      <dc:creator>HristoGrigorov</dc:creator>
      <dc:date>2020-02-05T04:22:37Z</dc:date>
    </item>
    <item>
      <title>Re: SMB syslog doesn't log action</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-syslog-doesn-t-log-action/m-p/74254#M2952</link>
      <description>&lt;P&gt;My 14XX with R77.20.87 are working fine.&lt;/P&gt;&lt;P&gt;Are you using 15XX appliances?&amp;nbsp;Must be an issue with the new R80.20 generation.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Feb 2020 17:49:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-syslog-doesn-t-log-action/m-p/74254#M2952</guid>
      <dc:creator>Pedro_Espindola</dc:creator>
      <dc:date>2020-02-05T17:49:06Z</dc:date>
    </item>
    <item>
      <title>Re: SMB syslog doesn't log action</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-syslog-doesn-t-log-action/m-p/74256#M2953</link>
      <description>&lt;P&gt;We've confirmed it does not work in r80.xx, but used to work in r77.&amp;nbsp; For some unknown reason, this was removed and apparently there are no plans to ever add it back.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Feb 2020 17:53:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-syslog-doesn-t-log-action/m-p/74256#M2953</guid>
      <dc:creator>Max_Baumgarten</dc:creator>
      <dc:date>2020-02-05T17:53:47Z</dc:date>
    </item>
    <item>
      <title>Re: SMB syslog doesn't log action</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-syslog-doesn-t-log-action/m-p/74257#M2954</link>
      <description>&lt;P&gt;Correct, it think the core issue is R80.20. I would down grade to R77.20 if that was an option at this point. I'm reaching out to some folks deeper in the org. If this can't be fixed I'm replacing these SMB devices with a different vendor.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Feb 2020 17:55:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-syslog-doesn-t-log-action/m-p/74257#M2954</guid>
      <dc:creator>John_Fleming</dc:creator>
      <dc:date>2020-02-05T17:55:49Z</dc:date>
    </item>
    <item>
      <title>Re: SMB syslog doesn't log action</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-syslog-doesn-t-log-action/m-p/74262#M2955</link>
      <description>&lt;P&gt;Go for PaloAlto Networks. These guys have some impressive syslogging:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/monitoring/use-syslog-for-monitoring/syslog-field-descriptions/traffic-log-fields" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/monitoring/use-syslog-for-monitoring/syslog-field-descriptions/traffic-log-fields&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Feb 2020 19:10:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-syslog-doesn-t-log-action/m-p/74262#M2955</guid>
      <dc:creator>HristoGrigorov</dc:creator>
      <dc:date>2020-02-05T19:10:36Z</dc:date>
    </item>
    <item>
      <title>Re: SMB syslog doesn't log action</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-syslog-doesn-t-log-action/m-p/74266#M2957</link>
      <description>&lt;P&gt;yes they do. That is a lot of data though. I wonder if they're using tcp syslog to avoid fragmenting the messages.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Feb 2020 19:55:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-syslog-doesn-t-log-action/m-p/74266#M2957</guid>
      <dc:creator>John_Fleming</dc:creator>
      <dc:date>2020-02-05T19:55:39Z</dc:date>
    </item>
    <item>
      <title>Re: SMB syslog doesn't log action</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-syslog-doesn-t-log-action/m-p/74272#M2958</link>
      <description>&lt;P&gt;Thank for raising this issue.&lt;/P&gt;
&lt;P&gt;From a quick internal investigation it seems this limitation was inherited from R80.20 enterprise version syslog feature.&lt;/P&gt;
&lt;P&gt;We are learning it in order to provide a solution.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Feb 2020 23:23:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-syslog-doesn-t-log-action/m-p/74272#M2958</guid>
      <dc:creator>Barel_Tkach</dc:creator>
      <dc:date>2020-02-05T23:23:49Z</dc:date>
    </item>
    <item>
      <title>Re: SMB syslog doesn't log action</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-syslog-doesn-t-log-action/m-p/74273#M2959</link>
      <description>&lt;P&gt;That is awesome and thank you so much for the update. Should my SR be re-opened?&lt;/P&gt;</description>
      <pubDate>Wed, 05 Feb 2020 23:34:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-syslog-doesn-t-log-action/m-p/74273#M2959</guid>
      <dc:creator>John_Fleming</dc:creator>
      <dc:date>2020-02-05T23:34:22Z</dc:date>
    </item>
    <item>
      <title>Re: SMB syslog doesn't log action</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-syslog-doesn-t-log-action/m-p/74343#M2960</link>
      <description>&lt;P&gt;Yes.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Feb 2020 14:59:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-syslog-doesn-t-log-action/m-p/74343#M2960</guid>
      <dc:creator>Barel_Tkach</dc:creator>
      <dc:date>2020-02-06T14:59:18Z</dc:date>
    </item>
  </channel>
</rss>

