Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
NorthernNetGuy
Advisor

remove logging from HTTPS inspection implied rules

I'm trying to remove logging for an implied HTTPS rule. My logs are getting filled with microsoft telemetry data that don't need to be logged. I create a rule so that they won't get logged, but it still occurs.

the inspection log shows the reason for it's bypass as "HTTPS inspection to a known software update service was bypassed" for self.events.data.microsoft.com

I can't seem to find the ssl inspection implied rule set, I didn't even know there was one.  Any help for this would be appreciated.

 

 

0 Kudos
2 Replies
PhoneBoy
Admin
Admin

The list of services automatically bypassed are documented here: https://support.checkpoint.com/results/sk/sk98655
This can also be disabled per the SK.
Whether you can disable the logging independently of that...not sure that can be done.
Suggest a TAC case: https://help.checkpoint.com 

0 Kudos
the_rock
Legend
Legend

I never even heard of such a thing even existed, https inspection implied rules, Im pretty sure it does, What Phoneboy gave you is probably your best bet.

Andy

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events