- Products
- Learn
- Local User Groups
- Partners
- More
CheckMates Fifth Birthday
Celebrate with Us!
days
hours
minutes
seconds
Join the CHECKMATES Everywhere Competition
Submit your picture to win!
Harmony Mobile 4:
New Version, New Capabilities
As YOU DESERVE THE BEST SECURITY
Upgrade to our latest GA Jumbo
CheckFlix!
All Videos In One Space
I have integrated my R80.40 Mgmt Server with Datadog SIEM.. in the IPS logs few key fields are missing such as Destination and Action.. i understand Destination field is not present by design as described in sksk136672.
However.. i am not sure if this is the case for "Action" field as well.. i am exporting raw logs via log exporter..
is there any specific setting to be enabled to get Action field or is this also a product limitation.
Thanks
The sk122323: Log Exporter - Check Point Log Export suggests: For information on Check Point's Log Fields Mapping, refer to sk144192. Here we can find the action field listed for Common Fields exported:
rule_action | Action | string | Action of the matched rule in the access policy |
Also for the blades Threat Extraction - Security Gateway & SandBlast Agent and Unified Policy (VPN-1 & FireWall-1) - Security Gateway:
action | Action | int |
Action of matched rule |
But there is no action field listed for Blade IPS (SmartDefense) - Security Gateway !
Thanks for the reply.. where can i find this table which you referred to ?
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY