- CheckMates
- :
- Products
- :
- Quantum
- :
- Management
- :
- Re: By default search query in Smart Console
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
By default search query in Smart Console
Is there any by a default search query for logs in Smart Console using ip-address(src name, dst name,host-name) according to these fields.!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Refer sk166092.
Also are you already using the favourites option for saved queries?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
no i'm not using any fav options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
How about: Logs View -> Tools -> Query Settings
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
yes..i need this custom default query according to ip-address like source and destination
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Simple example:
(src:10.10.10.10 AND dst:142.250.66.196 AND resource:www.google.com)
Others fields that may also be useful here amongst others are:
dst_domain_name:
tls_server_host_name:
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You can set it for a specific user in their installation of SmartConsole as Chris mentioned here: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...
You can also enforce a specific query using SmartView as described here: https://community.checkpoint.com/t5/Management/Limited-Permission-Profile/m-p/32868/thread-id/21934#...
