<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Security Logs in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Security-Logs/m-p/129456#M5755</link>
    <description>&lt;P&gt;Hello, I have recently had some doubts about some security logs in a 790 firewall, such as the following three examples:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="checkpoint_790_2021-09-14_21-58-42.jpg" style="width: 857px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/13713iBB68846C98781AEE/image-size/large?v=v2&amp;amp;px=999" role="button" title="checkpoint_790_2021-09-14_21-58-42.jpg" alt="checkpoint_790_2021-09-14_21-58-42.jpg" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="checkpoint_790_2021-09-14_21-59-05.jpg" style="width: 854px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/13712iF0B34C995FB11173/image-size/large?v=v2&amp;amp;px=999" role="button" title="checkpoint_790_2021-09-14_21-59-05.jpg" alt="checkpoint_790_2021-09-14_21-59-05.jpg" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="checkpoint_790_2021-09-14_22-04-13.jpg" style="width: 849px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/13714i3A358A254A47EA7F/image-size/large?v=v2&amp;amp;px=999" role="button" title="checkpoint_790_2021-09-14_22-04-13.jpg" alt="checkpoint_790_2021-09-14_22-04-13.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Both the source and the destination are servers on the same network segment, for example 180.80.0.0/24. The three events shown are sourced by the same server (180.80.0.10) but at two destinations (180.80.0.13, 180.80.0.14). This leads me to think that the 180.80.0.10 server has malware, but it has the Harmony Endpoint installed, I have verified and everything seems to be fine.&lt;/P&gt;&lt;P&gt;But the alerts keep coming constantly, what can I do in this case?&lt;/P&gt;&lt;P&gt;While on the other console of the 790, it tells me that it is infected.&lt;/P&gt;&lt;P&gt;￼_&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="checkpoint_790_2021-09-14_22-23-26.jpg" style="width: 445px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/13715i2A8E7181FD5AFC83/image-size/large?v=v2&amp;amp;px=999" role="button" title="checkpoint_790_2021-09-14_22-23-26.jpg" alt="checkpoint_790_2021-09-14_22-23-26.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 15 Sep 2021 03:25:12 GMT</pubDate>
    <dc:creator>gazette</dc:creator>
    <dc:date>2021-09-15T03:25:12Z</dc:date>
    <item>
      <title>Security Logs</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Security-Logs/m-p/129456#M5755</link>
      <description>&lt;P&gt;Hello, I have recently had some doubts about some security logs in a 790 firewall, such as the following three examples:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="checkpoint_790_2021-09-14_21-58-42.jpg" style="width: 857px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/13713iBB68846C98781AEE/image-size/large?v=v2&amp;amp;px=999" role="button" title="checkpoint_790_2021-09-14_21-58-42.jpg" alt="checkpoint_790_2021-09-14_21-58-42.jpg" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="checkpoint_790_2021-09-14_21-59-05.jpg" style="width: 854px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/13712iF0B34C995FB11173/image-size/large?v=v2&amp;amp;px=999" role="button" title="checkpoint_790_2021-09-14_21-59-05.jpg" alt="checkpoint_790_2021-09-14_21-59-05.jpg" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="checkpoint_790_2021-09-14_22-04-13.jpg" style="width: 849px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/13714i3A358A254A47EA7F/image-size/large?v=v2&amp;amp;px=999" role="button" title="checkpoint_790_2021-09-14_22-04-13.jpg" alt="checkpoint_790_2021-09-14_22-04-13.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Both the source and the destination are servers on the same network segment, for example 180.80.0.0/24. The three events shown are sourced by the same server (180.80.0.10) but at two destinations (180.80.0.13, 180.80.0.14). This leads me to think that the 180.80.0.10 server has malware, but it has the Harmony Endpoint installed, I have verified and everything seems to be fine.&lt;/P&gt;&lt;P&gt;But the alerts keep coming constantly, what can I do in this case?&lt;/P&gt;&lt;P&gt;While on the other console of the 790, it tells me that it is infected.&lt;/P&gt;&lt;P&gt;￼_&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="checkpoint_790_2021-09-14_22-23-26.jpg" style="width: 445px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/13715i2A8E7181FD5AFC83/image-size/large?v=v2&amp;amp;px=999" role="button" title="checkpoint_790_2021-09-14_22-23-26.jpg" alt="checkpoint_790_2021-09-14_22-23-26.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Sep 2021 03:25:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Security-Logs/m-p/129456#M5755</guid>
      <dc:creator>gazette</dc:creator>
      <dc:date>2021-09-15T03:25:12Z</dc:date>
    </item>
    <item>
      <title>Re: Security Logs</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Security-Logs/m-p/129460#M5756</link>
      <description>&lt;P&gt;Could very well be false positives.&lt;BR /&gt;Packet captures and a TAC case are definitely in order.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Sep 2021 05:29:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Security-Logs/m-p/129460#M5756</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-09-15T05:29:09Z</dc:date>
    </item>
    <item>
      <title>Re: Security Logs</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Security-Logs/m-p/129471#M5758</link>
      <description>&lt;P&gt;I would assume a false positive as the traffic is local, not to a C&amp;amp;C server...&lt;/P&gt;</description>
      <pubDate>Wed, 15 Sep 2021 08:21:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Security-Logs/m-p/129471#M5758</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2021-09-15T08:21:21Z</dc:date>
    </item>
  </channel>
</rss>

