IPS statistics
This information shows which matched IPS Protections cause a high load on the CPU. Here is a new command "fw pm_stats" for R81.
This command collects IPS & Pattern Matcher statistics for all patterns on the local machine for the specified number of seconds (in this example for 60 seconds):
Example:
# fw pm_stats collect_csv_on_demand 60
The output files are located in the current directory.
./pm_stat_collect.csv.tier1.csv -> Displays the statistics of the Pattern Matcher First Tier
./pm_stat_collect.csv.tier2.csv -> Displays the statistics of the Pattern Matcher Second Tier
Attention:
This command enables Pattern Matcher statistics for all patterns which consume more RAM and may reduce performance of a Gateway.
This command collects IPS & Pattern Matcher statistics for new IPS protections (protections with release date of less than 30 days)
Example:
# fw pm_stats collect_csv
By default the Pattern Matcher statistics is always enabled for new IPS protections, and the collection is without performance and memory impact.
------
➜ CCSM Elite, CCME, CCTE ➜ www.checkpoint.tips