- Products
- Learn
- Local User Groups
- Partners
- More
CheckMates Fifth Birthday
Celebrate with Us!
days
hours
minutes
seconds
Join the CHECKMATES Everywhere Competition
Submit your picture to win!
Check Point Proactive support
Free trial available for 90 Days!
As YOU DESERVE THE BEST SECURITY
Upgrade to our latest GA Jumbo
The 2022 MITRE Engenuity ATT&CK®
Evaluations Results Are In!
Now Available: SmartAwareness Security Training
Training Built to Educate and Engage
MITRE ATT&CK
Inside Check Point products!
CheckFlix!
All Videos In One Space
I have integrated my R80.40 Mgmt Server with Datadog SIEM.. in the IPS logs few key fields are missing such as Destination and Action.. i understand Destination field is not present by design as described in sksk136672.
However.. i am not sure if this is the case for "Action" field as well.. i am exporting raw logs via log exporter..
is there any specific setting to be enabled to get Action field or is this also a product limitation.
Thanks
The sk122323: Log Exporter - Check Point Log Export suggests: For information on Check Point's Log Fields Mapping, refer to sk144192. Here we can find the action field listed for Common Fields exported:
rule_action | Action | string | Action of the matched rule in the access policy |
Also for the blades Threat Extraction - Security Gateway & SandBlast Agent and Unified Policy (VPN-1 & FireWall-1) - Security Gateway:
action | Action | int |
Action of matched rule |
But there is no action field listed for Blade IPS (SmartDefense) - Security Gateway !
Thanks for the reply.. where can i find this table which you referred to ?
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY