Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
rhythmblueberry
Explorer

Custom Intelligence Feeds LOGS Smartconsole

Hi,

Can I see any prevent/detect logs if something match with an IOC Network feed that I configured inside Indicator section?

I did some tests but I can't see any log on smartconsole logs.

Anti-bot and Anti-virus blades are both enabled on gateway R81.20.

 

Thanks

0 Kudos
2 Replies
PhoneBoy
Admin
Admin

Did you upload an individual indicator, use ioc_feeds, or a Network Feed?
Either way, it SHOULD show in the full log card what was matched (assuming the policy configuration is correct).

0 Kudos
rhythmblueberry
Explorer

That's an IOC_FEED with an http server (unauthenticated just for test) and it works with connectivity test.

I have any as protected scope on TP Layer and anti-bot and anti-virus blade active also on scope.

Do you have an example of that log or a keyword in order to search that kind of log?

 

Thanks

 

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events