cancel
Showing results for 
Search instead for 
Did you mean: 
Create a Post
Logging and Reporting

Have questions about viewing logs with SmartView, generating reports with SmartEvent Event Management, or exporting logs to a SIEM with Log Exporter? This is where to ask!

Juraj_Skalny
Juraj_Skalny inside Logging and Reporting 7 hours ago
views 356 7 5

DNS Trap Protection

Hello Guys, I would like to follow up on the following posts :https://community.checkpoint.com/t5/Logging-and-Reporting/Threat-Prevention-dns-trap-and-resource-categorization/td-p/18638https://community.checkpoint.com/t5/IPS-Anti-Virus-Anti-Bot-Anti/Some-DNS-request-not-block-by-AV-blade/m-p/26588#M784 What we would like to find out is how log firewalls keeps the information about malicious domain in cache?DNS request is changed for Bogus IP by firewall as long as the malicious domain is in cache.The problem we see is that the cache is maybe too short as "Connection was allowed because background classification mode was set. See sk74120 for more information." for the same malicious domain appears in logs too often.We would expect to see this classification event once and then lots of changes to Bogus IP. But that is not the case.There is no documentation on CP covering this info or how to change it. Or we have just overlooked it.In our understanding this way lots of malicious activities are just allowed only because firewall needs to let go of DNS resolution requests because those needs to be classified in the first place over and over again.         Thanks and regards, Juraj
Aitor_Carazo
Aitor_Carazo inside Logging and Reporting 12 hours ago
views 187 1

[Smartevent] Mil Alerts Source and destination empty only with custom IOCs

Hi Checkmates,I have recently imported some custom IOCs. I have configured the Smartevent to send alerts with Virus and Bot events.When an event matches a custom IOC, the mail alert got the source and destination empty.This only happen with all the custom IOCs, with other events works fine.Regards 
B_P
B_P inside Logging and Reporting 16 hours ago
views 515 9

R80.30 Netflow Setup

Pre R80.10 Netflow worked fine.Now on R80.30 I have two flows that are identical -- but one only shows Outbound and the other only shows Inbound BUT -- and this is perplexing -- it is the exact same traffic for both inbound and outbound flows -- i.e. source and destination are the same.Yes.. let that simmer for a while.I have one rule that's configured on the firewall and it's a rule that a lot of web traffic hits on.I'm using ManageEngine's Netflow Analyzer.For this traffic, I would expect there should be one flow and it should include both inbound and outbound traffic on the one interface (the internal interface it's hitting).
Dan_Zada
inside Logging and Reporting yesterday
views 2631 32 9
Employee+

Log Exporter Filtering

Hello all,I'm happy to inform you that we added a new feature to the log exporter - the ability to filter logs.Starting today, you will be able to configure which logs will exported, based on fields and values, including complex statements.More information, including basic and advanced filtering instructions, can be found in SK122323.If you have any question or comment, let me know.Thanks!Dan.
Ruan_Kotze
Ruan_Kotze inside Logging and Reporting yesterday
views 55 1

Compliance Blade report includes excluded objects

Hi All,I'm working with a financial services sector entity, who uses the Compliance blade to help with their PCI-DSS compliance efforts.  The environment is based on R80.10In order to streamline audit reports, we've excluded all the gateways that are not in scope for PCI-DSS, however even in doing so all compliance reports include findings for all gateway objects.  It seems that excluded objects only applies for the dashboard view.Is this expected behaviour?Thanks,Ruan
Rene_Rolsted
Rene_Rolsted inside Logging and Reporting Monday
views 93 3

upgrade from R80.20 to R80.30 Log server don't send logs to Rapid7 SIEM

We have upgraded our management server to R80.30 and we have no problem.We have upgraded our Log server and this works fine.We log to Rapid7 and when we running R80.20 everything works great and we send logs to Rapid7But we have some errors in R80.30 and we don't send log to Rapid7 now.I use this guide:https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk122323#How%20does%20it%20WorkI make this commandcp_log_export add name Rapid7_new target-server 10.1.81.48 target-port 5149 protocol udp format syslog[Expert@fwmp05b1:0]# cp_log_export restart name Rapid7_newStopping log_exporter for: Rapid7_newcpwd_admin:Process EXPORTER.Rapid7_new (pid=24955) stopped with command "kill 24955". Exit code 0.Starting log_exporter for: Rapid7_newcpwd_admin:Process EXPORTER.Rapid7_new started successfully (pid=22531) [Expert@fwmp05b1:0]# cp_log_export statusname: Rapid7_newstatus: Running (22531)last log read at: N/Adebug file: /opt/CPrt-R80.30/log_exporter/targets/Rapid7_new/log/log_indexer.elg I get those errors when er read the .elg files[Expert@fwmp05b1:0]# more /opt/CPrt-R80.30/log_exporter/targets/Rapid7_new/log/log_indexer.elg [18 Nov 8:46:49] pfopen: failed to open /opt/CPsuite-R80.30/fw1/log/2019-11-01_204407_136.log[18 Nov 8:46:49] CBinaryFile::Open: failed to open file (/opt/CPsuite-R80.30/fw1/log/2019-11-01_204407_136.log) for reading[18 Nov 8:46:49] CBinaryFile::Open: exit status false[18 Nov 8:46:49] CMappedBinaryFile::error opening file /opt/CPsuite-R80.30/fw1/log/2019-11-01_204407_136.log[18 Nov 8:46:49] CLogFile::Open2: error: open (/opt/CPsuite-R80.30/fw1/log/2019-11-01_204407_136.log) for reading failed[log_indexer 22531 4063230784]@fwmp05b1[18 Nov 8:46:49] CpLogReader::Open: failed to open /opt/CPsuite-R80.30/fw1/log/2019-11-01_204407_136.log[18 Nov 8:46:49] pfopen: failed to open /opt/CPsuite-R80.30/fw1/log/2019-11-01_235900.log[18 Nov 8:46:49] CBinaryFile::Open: failed to open file (/opt/CPsuite-R80.30/fw1/log/2019-11-01_235900.log) for reading[18 Nov 8:46:49] CBinaryFile::Open: exit status false[18 Nov 8:46:49] CMappedBinaryFile::error opening file /opt/CPsuite-R80.30/fw1/log/2019-11-01_235900.log[18 Nov 8:46:49] CLogFile::Open2: error: open (/opt/CPsuite-R80.30/fw1/log/2019-11-01_235900.log) for reading failed[log_indexer 22531 4063230784]@fwmp05b1[18 Nov 8:46:49] CpLogReader::Open: failed to open /opt/CPsuite-R80.30/fw1/log/2019-11-01_235900.log[18 Nov 8:46:49] pfopen: failed to open /opt/CPsuite-R80.30/fw1/log/2019-11-02_000000.log[18 Nov 8:46:49] CBinaryFile::Open: failed to open file (/opt/CPsuite-R80.30/fw1/log/2019-11-02_000000.log) for reading[18 Nov 8:46:49] CBinaryFile::Open: exit status false[18 Nov 8:46:49] CMappedBinaryFile::error opening file /opt/CPsuite-R80.30/fw1/log/2019-11-02_000000.log[18 Nov 8:46:49] CLogFile::Open2: error: open (/opt/CPsuite-R80.30/fw1/log/2019-11-02_000000.log) for reading failed[log_indexer 22531 4063230784]@fwmp05b1[18 Nov 8:46:49] CpLogReader::Open: failed to open /opt/CPsuite-R80.30/fw1/log/2019-11-02_000000.log[18 Nov 8:46:49] pfopen: failed to open /opt/CPsuite-R80.30/fw1/log/2019-11-02_120246_137.log[18 Nov 8:46:49] CBinaryFile::Open: failed to open file (/opt/CPsuite-R80.30/fw1/log/2019-11-02_120246_137.log) for reading[18 Nov 8:46:49] CBinaryFile::Open: exit status false[18 Nov 8:46:49] CMappedBinaryFile::error opening file /opt/CPsuite-R80.30/fw1/log/2019-11-02_120246_137.log[18 Nov 8:46:49] CLogFile::Open2: error: open (/opt/CPsuite-R80.30/fw1/log/2019-11-02_120246_137.log) for reading failed[log_indexer 22531 4063230784]@fwmp05b1[18 Nov 8:46:49] CpLogReader::Open: failed to open /opt/CPsuite-R80.30/fw1/log/2019-11-02_120246_137.log[18 Nov 8:46:49] pfopen: failed to open /opt/CPsuite-R80.30/fw1/log/2019-11-02_235900.log[18 Nov 8:46:49] CBinaryFile::Open: failed to open file (/opt/CPsuite-R80.30/fw1/log/2019-11-02_235900.log) for reading[18 Nov 8:46:49] CBinaryFile::Open: exit status false[18 Nov 8:46:49] CMappedBinaryFile::error opening file /opt/CPsuite-R80.30/fw1/log/2019-11-02_235900.log[18 Nov 8:46:49] CLogFile::Open2: error: open (/opt/CPsuite-R80.30/fw1/log/2019-11-02_235900.log) for reading failed[log_indexer 22531 4063230784]@fwmp05b1[18 Nov 8:46:49] CpLogReader::Open: failed to open /opt/CPsuite-R80.30/fw1/log/2019-11-02_235900.log[18 Nov 8:46:49] pfopen: failed to open /opt/CPsuite-R80.30/fw1/log/2019-11-03_000000.log[18 Nov 8:46:49] CBinaryFile::Open: failed to open file (/opt/CPsuite-R80.30/fw1/log/2019-11-03_000000.log) for reading[18 Nov 8:46:49] CBinaryFile::Open: exit status false[18 Nov 8:46:49] CMappedBinaryFile::error opening file /opt/CPsuite-R80.30/fw1/log/2019-11-03_000000.log[18 Nov 8:46:49] CLogFile::Open2: error: open (/opt/CPsuite-R80.30/fw1/log/2019-11-03_000000.log) for reading failed[log_indexer 22531 4063230784]@fwmp05b1[18 Nov 8:46:49] CpLogReader::Open: failed to open /opt/CPsuite-R80.30/fw1/log/2019-11-03_000000.log[log_indexer 22531 4063230784]@fwmp05b1[18 Nov 8:46:49] LogFetcher::CreateSessions - 127.0.0.1:fw.log [1574031600][log_indexer 22531 4063230784]@fwmp05b1[18 Nov 8:46:49] 127.0.0.1:fw.log [1574031600] create session for [15945957-4294967295][log_indexer 22531 4063230784]@fwmp05b1[18 Nov 8:46:49] LogFetcher::CreateSessions - 127.0.0.1:2019-11-14_105325_5.log [1573686000][log_indexer 22531 4063230784]@fwmp05b1[18 Nov 8:46:49] 127.0.0.1:2019-11-14_105325_5.log [1573686000] Too old - skipping[log_indexer 22531 4063230784]@fwmp05b1[18 Nov 8:46:49] LogFetcher::CreateSessions - 127.0.0.1:2019-11-14_000000.log [1573685940][log_indexer 22531 4063230784]@fwmp05b1[18 Nov 8:46:49] 127.0.0.1:2019-11-14_000000.log [1573685940] Too old - skipping[log_indexer 22531 4063230784]@fwmp05b1[18 Nov 8:46:49] LogFetcher::CreateSessions - 127.0.0.1:2019-11-13_235900.log [1573667904][log_indexer 22531 4063230784]@fwmp05b1[18 Nov 8:46:49] 127.0.0.1:2019-11-13_235900.log [1573667904] Too old - skipping[log_indexer 22531 4063230784]@fwmp05b1[18 Nov 8:46:49] LogFetcher::CreateSessions - 127.0.0.1:2019-11-13_185824_4.log [1573637844][log_indexer 22531 4063230784]@fwmp05b1[18 Nov 8:46:49] 127.0.0.1:2019-11-13_185824_4.log [1573637844] Too old - skipping[log_indexer 22531 4063230784]@fwmp05b1[18 Nov 8:46:49] LogFetcher::CreateSessions - 127.0.0.1:2019-11-13_103724_3.log [1573599600][log_indexer 22531 4063230784]@fwmp05b1[18 Nov 8:46:49] 127.0.0.1:2019-11-13_103724_3.log [1573599600] Too old - skipping[log_indexer 22531 4063230784]@fwmp05b1[18 Nov 8:46:49] LogFetcher::CreateSessions - 127.0.0.1:2019-11-13_000000.log [1573599540][log_indexer 22531 4063230784]@fwmp05b1[18 Nov 8:46:49] 127.0.0.1:2019-11-13_000000.log [1573599540] Too old - skipping[log_indexer 22531 4063230784]@fwmp05b1[18 Nov 8:46:49] LogFetcher::CreateSessions - 127.0.0.1:2019-11-12_235900.log [1573586634][log_indexer 22531 4063230784]@fwmp05b1[18 Nov 8:46:49] 127.0.0.1:2019-11-12_235900.log [1573586634] Too old - skipping[log_indexer 22531 4063230784]@fwmp05b1[18 Nov 8:46:49] LogFetcher::CreateSessions - 127.0.0.1:2019-11-12_202353_2.log [1573554853][log_indexer 22531 4063230784]@fwmp05b1[18 Nov 8:46:49] 127.0.0.1:2019-11-12_202353_2.log [1573554853] Too old - skipping[log_indexer 22531 4063230784]@fwmp05b1[18 Nov 8:46:49] LogFetcher::CreateSessions - 127.0.0.1:2019-11-12_113412_1.log [1573513200][log_indexer 22531 4063230784]@fwmp05b1[18 Nov 8:46:49] 127.0.0.1:2019-11-12_113412_1.log [1573513200] Too old - skipping[log_indexer 22531 4063230784]@fwmp05b1[18 Nov 8:46:49] LogFetcher::CreateSessions - 127.0.0.1:2019-11-12_000000.log [1573513140][log_indexer 22531 4063230784]@fwmp05b1[18 Nov 8:46:49] 127.0.0.1:2019-11-12_000000.log [1573513140] Too old - skipping[log_indexer 22531 4063230784]@fwmp05b1[18 Nov 8:46:49] LogFetcher::CreateSessions - 127.0.0.1:2019-11-11_235900.log [1573489314][log_indexer 22531 4063230784]@fwmp05b1[18 Nov 8:46:49] 127.0.0.1:2019-11-11_235900.log [1573489314] Too old - skipping[log_indexer 22531 4063230784]@fwmp05b1[18 Nov 8:46:49] LogFetcher::CreateSessions - 127.0.0.1:2019-11-11_172154_5.log [1573469158][log_indexer 22531 4063230784]@fwmp05b1[18 Nov 8:46:49] 127.0.0.1:2019-11-11_172154_5.log [1573469158] Too old - skipping[log_indexer 22531 4063230784]@fwmp05b1[18 Nov 8:46:49] LogFetcher::CreateSessions - 127.0.0.1:2019-11-11_114557_4.log [1573426800][log_indexer 22531 4063230784]@fwmp05b1[18 Nov 8:46:49] 127.0.0.1:2019-11-11_114557_4.log [1573426800] Too old - skipping[log_indexer 22531 4063230784]@fwmp05b1[18 Nov 8:46:49] LogFetcher::CreateSessions - 127.0.0.1:2019-11-11_000000.log [1573426740][log_indexer 22531 4063230784]@fwmp05b1[18 Nov 8:46:49] 127.0.0.1:2019-11-11_000000.log [1573426740] Too old - skipping[log_indexer 22531 4063230784]@fwmp05b1[18 Nov 8:46:49] LogFetcher::CreateSessions - 127.0.0.1:2019-11-10_235900.log [1573392274][log_indexer 22531 4063230784]@fwmp05b1[18 Nov 8:46:49] 127.0.0.1:2019-11-10_235900.log [1573392274] Too old - skipping[log_indexer 22531 4063230784]@fwmp05b1[18 Nov 8:46:49] LogFetcher::CreateSessions - 127.0.0.1:2019-11-10_142434_3.log [1573340400][log_indexer 22531 4063230784]@fwmp05b1[18 Nov 8:46:49] 127.0.0.1:2019-11-10_142434_3.log [1573340400] Too old - skipping[log_indexer 22531 4063230784]@fwmp05b1[18 Nov 8:46:49] LogFetcher::CreateSessions - 127.0.0.1:2019-11-10_000000.log [1573340341][log_indexer 22531 4063230784]@fwmp05b1[18 Nov 8:46:49] 127.0.0.1:2019-11-10_000000.log [1573340341] Too old - skipping[log_indexer 22531 4063230784]@fwmp05b1[18 Nov 8:46:49] LogFetcher::CreateSessions - 127.0.0.1:2019-11-09_235900.log [1573299121][log_indexer 22531 4063230784]@fwmp05b1[18 Nov 8:46:49] 127.0.0.1:2019-11-09_235900.log [1573299121] Too old - skipping[log_indexer 22531 4063230784]@fwmp05b1[18 Nov 8:46:49] LogFetcher::CreateSessions - 127.0.0.1:2019-11-09_123200_2.log [1573254000][log_indexer 22531 4063230784]@fwmp05b1[18 Nov 8:46:49] 127.0.0.1:2019-11-09_123200_2.log [1573254000] Too old - skipping[log_indexer 22531 4063230784]@fwmp05b1[18 Nov 8:46:49] LogFetcher::CreateSessions - 127.0.0.1:2019-11-09_000000.log [1573253940][log_indexer 22531 4063230784]@fwmp05b1[18 Nov 8:46:49] 127.0.0.1:2019-11-09_000000.log [1573253940] Too old - skipping[log_indexer 22531 4063230784]@fwmp05b1[18 Nov 8:46:49] LogFetcher::CreateSessions - 127.0.0.1:2019-11-08_235900.log [1573232635][log_indexer 22531 4063230784]@fwmp05b1[18 Nov 8:46:49] 127.0.0.1:2019-11-08_235900.log [1573232635] Too old - skipping[log_indexer 22531 4063230784]@fwmp05b1[18 Nov 8:46:49] LogFetcher::CreateSessions - 127.0.0.1:2019-11-08_180355_1.log [1573167600][log_indexer 22531 4063230784]@fwmp05b1[18 Nov 8:46:49] 127.0.0.1:2019-11-08_180355_1.log [1573167600] Too old - skipping[log_indexer 22531 4063230784]@fwmp05b1[18 Nov 8:46:49] LogFetcher::CreateSessions - 127.0.0.1:2019-11-08_000000.log [1573167540][log_indexer 22531 4063230784]@fwmp05b1[18 Nov 8:46:49] 127.0.0.1:2019-11-08_000000.log [1573167540] Too old - skipping[log_indexer 22531 4063230784]@fwmp05b1[18 Nov 8:46:49] LogFetcher::CreateSessions - 127.0.0.1:2019-11-07_235900.log [1573116154][log_indexer 22531 4063230784]@fwmp05b1[18 Nov 8:46:49] 127.0.0.1:2019-11-07_235900.log [1573116154] Too old - skipping[log_indexer 22531 4063230784]@fwmp05b1[18 Nov 8:46:49] LogFetcher::CreateSessions - 127.0.0.1:2019-11-07_094234.log [1573115413][log_indexer 22531 4063230784]@fwmp05b1[18 Nov 8:46:49] 127.0.0.1:2019-11-07_094234.log [1573115413] Too old - skipping[log_indexer 22531 4063230784]@fwmp05b1[18 Nov 8:46:49] LogFetcher::CreateSessions - 127.0.0.1:2019-11-07_093013_146.log [1573081201][log_indexer 22531 4063230784]@fwmp05b1[18 Nov 8:46:49] 127.0.0.1:2019-11-07_093013_146.log [1573081201] Too old - skipping[log_indexer 22531 4063230784]@fwmp05b1[18 Nov 8:46:49] LogFetcher::CreateSessions - 127.0.0.1:2019-11-07_000000.log [1573081140][log_indexer 22531 4063230784]@fwmp05b1[18 Nov 8:46:49] 127.0.0.1:2019-11-07_000000.log [1573081140] Too old - skipping[log_indexer 22531 4063230784]@fwmp05b1[18 Nov 8:46:49] LogFetcher::CreateSessions - 127.0.0.1:2019-11-06_235900.log [1573066644][log_indexer 22531 4063230784]@fwmp05b1[18 Nov 8:46:49] 127.0.0.1:2019-11-06_235900.log [1573066644] Too old - skipping[log_indexer 22531 4063230784]@fwmp05b1[18 Nov 8:46:49] LogFetcher::CreateSessions - 127.0.0.1:2019-11-06_195724_145.log [1573034048][log_indexer 22531 4063230784]@fwmp05b1[18 Nov 8:46:49] 127.0.0.1:2019-11-06_195724_145.log [1573034048] Too old - skipping[log_indexer 22531 4063230784]@fwmp05b1[18 Nov 8:46:49] LogFetcher::CreateSessions - 127.0.0.1:2019-11-06_105407_144.log [1572994800][log_indexer 22531 4063230784]@fwmp05b1[18 Nov 8:46:49] 127.0.0.1:2019-11-06_105407_144.log [1572994800] Too old - skipping[log_indexer 22531 4063230784]@fwmp05b1[18 Nov 8:46:49] LogFetcher::CreateSessions - 127.0.0.1:2019-11-06_000000.log [1572994741][log_indexer 22531 4063230784]@fwmp05b1[18 Nov 8:46:49] 127.0.0.1:2019-11-06_000000.log [1572994741] Too old - skipping[log_indexer 22531 4063230784]@fwmp05b1[18 Nov 8:46:49] LogFetcher::CreateSessions - 127.0.0.1:2019-11-05_235900.log [1572978346][log_indexer 22531 4063230784]@fwmp05b1[18 Nov 8:46:49] 127.0.0.1:2019-11-05_235900.log [1572978346] Too old - skipping[log_indexer 22531 4063230784]@fwmp05b1[18 Nov 8:46:49] LogFetcher::CreateSessions - 127.0.0.1:2019-11-05_192546_143.log [1572947023][log_indexer 22531 4063230784]@fwmp05b1[18 Nov 8:46:49] 127.0.0.1:2019-11-05_192546_143.log [1572947023] Too old - skipping[log_indexer 22531 4063230784]@fwmp05b1[18 Nov 8:46:49] LogFetcher::CreateSessions - 127.0.0.1:2019-11-05_104342_142.log [1572908400][log_indexer 22531 4063230784]@fwmp05b1[18 Nov 8:46:49] 127.0.0.1:2019-11-05_104342_142.log [1572908400] Too old - skipping[log_indexer 22531 4063230784]@fwmp05b1[18 Nov 8:46:49] LogFetcher::CreateSessions - 127.0.0.1:2019-11-05_000000.log [1572908341][log_indexer 22531 4063230784]@fwmp05b1[18 Nov 8:46:49] 127.0.0.1:2019-11-05_000000.log [1572908341] Too old - skipping[log_indexer 22531 4063230784]@fwmp05b1[18 Nov 8:46:49] LogFetcher::CreateSessions - 127.0.0.1:2019-11-04_235900.log [1572905198][log_indexer 22531 4063230784]@fwmp05b1[18 Nov 8:46:49] 127.0.0.1:2019-11-04_235900.log [1572905198] Too old - skipping[log_indexer 22531 4063230784]@fwmp05b1[18 Nov 8:46:49] LogFetcher::CreateSessions - 127.0.0.1:2019-11-04_230638_141.log [1572872640][log_indexer 22531 4063230784]@fwmp05b1[18 Nov 8:46:49] 127.0.0.1:2019-11-04_230638_141.log [1572872640] Too old - skipping[log_indexer 22531 4063230784]@fwmp05b1[18 Nov 8:46:49] LogFetcher::CreateSessions - 127.0.0.1:2019-11-04_140359_140.log [1572849950][log_indexer 22531 4063230784]@fwmp05b1[18 Nov 8:46:49] 127.0.0.1:2019-11-04_140359_140.log [1572849950] Too old - skipping[log_indexer 22531 4063230784]@fwmp05b1[18 Nov 8:46:49] LogFetcher::CreateSessions - 127.0.0.1:2019-11-04_074550_139.log [1572822000][log_indexer 22531 4063230784]@fwmp05b1[18 Nov 8:46:49] 127.0.0.1:2019-11-04_074550_139.log [1572822000] Too old - skipping[log_indexer 22531 4063230784]@fwmp05b1[18 Nov 8:46:49] LogFetcher::CreateSessions - 127.0.0.1:2019-11-04_000000.log [1572821941][log_indexer 22531 4063230784]@fwmp05b1[18 Nov 8:46:49] 127.0.0.1:2019-11-04_000000.log [1572821941] Too old - skipping[log_indexer 22531 4063230784]@fwmp05b1[18 Nov 8:46:49] LogFetcher::CreateSessions - 127.0.0.1:2019-11-03_235900.log [1572783445][log_indexer 22531 4063230784]@fwmp05b1[18 Nov 8:46:49] 127.0.0.1:2019-11-03_235900.log [1572783445] Too old - skipping[log_indexer 22531 4063230784]@fwmp05b1[18 Nov 8:46:49] LogFetcher::CreateSessions - 127.0.0.1:2019-11-03_131724_138.log [1572735600][log_indexer 22531 4063230784]@fwmp05b1[18 Nov 8:46:49] 127.0.0.1:2019-11-03_131724_138.log [1572735600] Too old - skipping[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:50] Read Log Format field name:['product'][log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:50] Read Log Format field name:['__policy_id_tag'][log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:50] Read Log Format field name:['inzone'][log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:50] Read Log Format field name:['outzone'][log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:50] Read Log Format field name:['src'][log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:50] Read Log Format field name:['s_port'][log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:50] Read Log Format field name:['dst'][log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:50] Read Log Format field name:['service'][log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:50] Read Log Format field name:['proto'][log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:50] Read Log Format field name:['xlatesrc'][log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:50] Read Log Format field name:['xlatedst'][log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:50] Read Log Format field name:['xlatesport'][log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:50] Read Log Format field name:['xlatedport'][log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:50] Read Log Format field name:['nat_rulenum'][log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:50] Read Log Format field name:['nat_addtnl_rulenum'][log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:50] Read Log Format field name:['match_table'][log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:50] markFieldIfItShouldBeAddToLogHeaderFormat: Mark as Header on position: 2 field:time[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:50] LogFormatExtractor::prepareFieldGetterForField nFieldType == eFtTable[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:50] LogFormatExtractor::prepareFieldGetterForField - Read fields format from table:match_table[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:50] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:50] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:50] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:50] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:50] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:50] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:50] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:50] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:50] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:50] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:50] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:50] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:50] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:50] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:50] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:50] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:50] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:50] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:50] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:50] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:50] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:50] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:50] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:50] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:50] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:50] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:50] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:50] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:50] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:50] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:50] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:50] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:50] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:50] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:50] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:50] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:50] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:50] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:50] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:50] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:51] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:51] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:51] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:51] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:51] ActionTranslator::GetActionString - error - failed to find action string for action number [24] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:51] ActionTranslator::GetActionString - error - failed to find action string for action number [24] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:51] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:51] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:51] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:51] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:51] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:51] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:51] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:51] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:51] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:51] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:51] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:51] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:51] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:51] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:51] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:51] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:51] ActionTranslator::GetActionString - error - failed to find action string for action number [24] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:51] ActionTranslator::GetActionString - error - failed to find action string for action number [24] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:51] ActionTranslator::GetActionString - error - failed to find action string for action number [24] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:51] ActionTranslator::GetActionString - error - failed to find action string for action number [24] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:51] ActionTranslator::GetActionString - error - failed to find action string for action number [24] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:51] ActionTranslator::GetActionString - error - failed to find action string for action number [24] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:51] ActionTranslator::GetActionString - error - failed to find action string for action number [24] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:51] ActionTranslator::GetActionString - error - failed to find action string for action number [24] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:51] ActionTranslator::GetActionString - error - failed to find action string for action number [24] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:51] ActionTranslator::GetActionString - error - failed to find action string for action number [24] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:51] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:51] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:51] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:51] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:51] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:51] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:51] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:51] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:51] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:51] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:52] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:52] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:52] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:52] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:52] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:52] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:52] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:52] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:52] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:52] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:52] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:52] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:52] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:52] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:52] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:52] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:52] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:52] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:52] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:52] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:52] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:52] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:52] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:52] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:52] ActionTranslator::GetActionString - error - failed to find action string for action number [24] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:52] ActionTranslator::GetActionString - error - failed to find action string for action number [24] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:52] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:52] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:52] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:52] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:52] ActionTranslator::GetActionString - error - failed to find action string for action number [24] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:52] ActionTranslator::GetActionString - error - failed to find action string for action number [24] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:53] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:53] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:53] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:53] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:53] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:53] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:53] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:53] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:53] ActionTranslator::GetActionString - error - failed to find action string for action number [25] returning empty action[log_indexer 22531 4107270976]@fwmp05b1[18 Nov 8:46:53] ActionTranslator::GetActionString - error - failed to find action string for action number [25] Some who know about this problem or have a solution?Best regardsRené Rolsted   
Chinmaya_Naik
Chinmaya_Naik inside Logging and Reporting Monday
views 313 2

Forescout Integration with checkpoint management Server

Hi Team,We are trying to integrate Forcscout with the checkpoint.Gaia OS R80.20 with jumbo take_103Communication happens in between Checkpoint MGMT and  Forescout.From Forescout able to telnet with 18184 port to Checkpoint MGMT.Refer the below screenshot for detailsStill, face the below error:- Pls, help to resolve the issue. Regards,@Chinmaya_Naik 
sajin
sajin inside Logging and Reporting Monday
views 2054 8 1

Smart Event not showing Accepted Log

Smart Event not showing Accepted and the Clean up rule is ANY ANY ALLOW. In the Event when i select the policy package in the filter, the ACCEPT logs shows 0. I changed the Log  to Detailed and Extended and after the Accept log was available but when expanding the logs again it shows only DETECT logs.Please any one help on this issue.
TheRealDiZ
TheRealDiZ inside Logging and Reporting Monday
views 523 10

NAT Rule Number 0

Hi Guys,We got some weird issues with NAT on R80.20 (no hf installed).When we check logs we notice that basically the traffic was hitting a rule called "NAT Rule Number 0".What does it stands for?I have tried to check NAT Rules/Objects/implied rules/global properties and I was not able to find anything related to it or anything related to NAT for that specific network/objects. Let me know,RealD!Z
Henning_Aga
Henning_Aga inside Logging and Reporting Sunday
views 692 4 1

Cannot add log server to smartevent

We have configured SmartEvent R80.10 (dedicated) and by following sk110894 gotten av few domains and logs into SmartEvent. (We get the "Correlating logs to events. The log correlation unit is not able to read logs from Log server: . Please run 'cpstat cpsead' " but we see logs and events, so we're assuming this is cosmetic). However, we are _only_ so far able to add logs from domains where the firewall logs to a dedicated log server. If the firewalls in the domain we add log to the management, it does not appear in "General settings -> Inital settings -> Correlation Units -> Add (select domain where firewall logs to managment (not do dedicated log server). Anybody seen anything similar.
PeterH
PeterH inside Logging and Reporting Friday
views 115 1

Syslog Parser for Juniper SRX

I tried to parse syslog messges from SRX devices int Check Point SmartLog.The following fields are working well:Time: Blade:Origin:Action:Source:Destination Now I would like to integrate also the service as well the the whole NAT xlates.The syslog stream looks like this: RegardsPeter  
Michal_Gans
Michal_Gans inside Logging and Reporting Friday
views 146 3

Export log from ChP EndPoint management to central ChP management by Log Exporter

Hi,Customer have two MultiDomainManagementServers to control all ChP gateways, this two MDSs are connected with SmartEvent. He also have one SingleDomainManagement just for EndPoint security. I would like to start forwarding all logs from SDM to MDM (specific CMA). Something similar is described in sk35288, but it's not the same and it's not very elegant way to do it. I would prefer to use Log Exporter for it but TAC told me, that this is not supported solution. To be honest I don't understand why, management already can receive syslog so it's all about sending it in right format (should be easy to implement it to Log Exporter).  I would like to know, if anyone of you have similar problem as I have and if so how you solved it.  
Bishal_Upadhyay
Bishal_Upadhyay inside Logging and Reporting Friday
views 1874 13 3

Smartview stuck as loading smartview.. in R80.20

Smartview is not working in new tab of Logs, also it is not loading with https://<Mgmt IP>/smartview.The warning appears which is attached herewith.We are running distributed architecture with firewalls on high availability and running Gaia OS R80.20.We tried disabling and enabling Smart Event blades on Mgmt. Also tried evstop and evstart; and also $RTDIR/scripts/stopSmartView and $RTDIR/scripts/startSmartView
israelgl
israelgl inside Logging and Reporting Thursday
views 356 2

Report\View - unable to filter ssh_version_2 service

hey alli tried to create a report on ssh_version_2 traffic and unable to filter it.when i filtered by ssh, i only saw SSH v1 traffic that was blocked because SSH v1 are not allowed by policy.but no mater how i tried to filter the report to all SSH traffic or ssh_version_2 traffic, i didn't get any results of ssh version 2.in the logs i see the ssh_version_2 logs, and i can filter the log by this service.any idea why it's acting like this?  
brk_01
brk_01 inside Logging and Reporting a week ago
views 170 2

fw monitor - traffic dropped after i

I have ike (udp/500) traffic coming, and it's getting dropped after i in fw monitor.Log show that it was being dropped due to CPearlydrop.. changed early drop optimization to 0 so I can see it in the logs, and it's just bypassing my rule and hitting the default drop any.[vs_0][fw_33] eth1-01:i[492]: x.x.x.x  -> y.y.y.y (UDP) len=492 id=30892UDP: 500 -> 500[vs_0][fw_3] eth1-01:i[492]: x.x.x.x -> y.y.y.y (UDP) len=492 id=31502UDP: 500 -> 500my rule, i'm allowing x.x.x.x to y.y.y.y (which is static NAT), with IKE, gIKE, udp/500, udp/4500 all allowed.Can't figure out what I'm missing here.