- Products
- Learn
- Local User Groups
- Partners
- More
Policy Insights and Policy Auditor in Action
19 November @ 5pm CET / 11am ET
Access Control and Threat Prevention Best Practices
Watch HereOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello Everyone,
As part of implementing SIEM solution in our organization i got a request from the CISO to log from the endpoint what process generates traffic.
i can see in sk144192 that there is a "process_name" field under "Harmony Endpoint - Common Fields".
unfortunately, i cannot find this field in actual logs for firewall, TP, Anti-Malware or Anti-Bot blades. is there anything specific i should enable for the client to log this information?
Best Regards,
Yossi.
Hey Yossi,
Let me check this in the lab later.
Best,
Andy
Sorry, just working on some Azure stuff now, but have you tried below query to see if it yields anything?
Andy
blade:"Endpoint Compliance"
this query is works of course, but i cannot see how it is related to my issue 🙂
Thank you.
No no, I get that, I was just curious if it worked or not. I will check again in a bit, but you may want to open the support case in the meantime to confirm.
Andy
process_name refers to the (potentially) malicious process that is being blocked, not the blade that blocked it.
Based on this SK, it would seem we don't log which blade is responsible for the block, though it can be inferred from the other fields included.
Hi PhoneBoy,
this is exactly the information i need, the process who is made the traffic and being blocked/allow.
Best Regards,
Yossi.
Did you end up opening TAC case to see if you can verify that info, if its possible?
Best,
Andy
The only place it would show...when it is relevant...is in the full log card.
In any case, you may need to consult with TAC here: https://help.checkpoint.com
Thank you all, i opened a ticket and wait for an answer.
Let us know what they say.
Best,
Andy
After TAC investigation my request is not possible. so we achieve this logs through Sysmon.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 |
Wed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY