- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Announcing Quantum R82.10!
Learn MoreOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello,
So what I want to do is, get a distinct (i.e. unique items) list of what rules were hit with a certain filter in place. E.g. Give all rules hit in the last month for filter "src:192.168.1.0/24 OR dst:192.168.1.0/24". All of them not just the top ten or something.
SmartConsole (Logs) do not seem to be able to produce this information on the fly, i.e. that does not seem to be something you can specify as a query like in SQL (using SELECT DISTINCT) or otherwise.
Smartconsole does not generate exports, but Smartview does. So I tried that.
When I start an export with maximum amount of data (1M), nothing happens, it stays running in "Tasks->Archive" screen and searches are meanwhile no longer working, so I had to reboot smartcenter.
What do I need to do to obtain this simple piece of information without assigning it a dozen CPU cores and tens or hundreds of gigabytes of RAM (which is I guess the issue with an export)?
Thanks.
It’s just a spontaneous idea from me.
You can possibly do this with SmartEvent and generate a report for it.
I see point Heiko made. I have dedicated smart event in the lab, let me see if I can make this work.
Thanks for the effort, but we don't have a license for that.
I'll just go through the Policy and apply a filter with Packet Mode enabled and hope I don't miss anything.
You mean license for smart event? If not, you can try eval.
On top of screenshots I sent, will do some more tests tomorrow in the lab to see what the final report would look like.
Exports from SmartView works, you just need to wait 😉 It can take up to 30 minutes to generate the export, depending on amout of logs and selected filter.
One issue in case of SmartView export is that you need to ensure each and every rule has Log enabled.
Another option would be to create some script to get all rules from specific rulebase and check for hits within specific timeframe.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 22 | |
| 15 | |
| 11 | |
| 7 | |
| 6 | |
| 5 | |
| 4 | |
| 4 | |
| 4 | |
| 4 |
Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY