- CheckMates
- :
- Products
- :
- General Topics
- :
- Alert about increase in a specific type of log ("F...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Alert about increase in a specific type of log ("First packet isn't SYN" for me)
Hello guys,
I have a firewall gateway cluster with a manager, version 81.10. I am looking for ways to get an alert about an increase of the log "First packet isn't SYN", whether it is with skyline or some other alert mechanism, through the api or even a cli command that would let me do a query on the logs.
If anyone has suggestions I would love to hear. Thanks:)
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
If it shows up in a search (e.g. with SmartView), you can query via API here: https://sc1.checkpoint.com/documents/latest/APIs/index.html#cli/show-logs~v2%20
Whether these kinds of messages are "indexed" or not is a separate question.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @bob111
- I suggest you to upgrade it to R81.20 because the support of R81.10 will expired soon. 🙂
- Are you sending the logs to any kind SIEM?
- Have you checked the features of the SmartEvent?
- I am not 100% sure, maybe you can set such kind of threshold there
Akos
\m/_(>_<)_\m/
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
If it shows up in a search (e.g. with SmartView), you can query via API here: https://sc1.checkpoint.com/documents/latest/APIs/index.html#cli/show-logs~v2%20
Whether these kinds of messages are "indexed" or not is a separate question.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thank you very much, exactly what I was looking for!
