Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Danny
MVP Gold
MVP Gold

HTTPS Inspection in SmartEvent shows no data

I copied the Rule UID of a HTTPS inspection rule to my clipboard.

image.png

I'm able to filter for this UID in SmartLog, however I'm unable to filter for it within SmartEvent / SmartView.
Is this a limitation? The behaviour is identical in every R81 / R81.10 environment I tried.

My goal was to create SmartEvent View for HTTPS Inspection to show the top HTTPSi bypass rules etc.

I checked sk144192 but I found no way to use these log fields in SmartEvent:

Security Gateway - HTTPS Inspection Fields
https_inspection_rule_id HTTPS Inspection Rule ID string ID of the matched rule
https_inspection_rule_name HTTPS Inspection Rule Name string Name of the matched rule
app_properties Additional Categories string List of all found categories
resource Resource string HTTPS resource
Possible values: SNI or domain name
https_validation HTTPS Validation string Precise error, describing HTTPS inspection failure
https_inspection_action Inspection Action string HTTPS Inspection action (Inspect/Bypass/Error)

 

It seems that SmartEvent only has these two HTTPS Inspection fields:

image.png

0 Kudos
4 Replies
PhoneBoy
Admin
Admin

Did you try just filtering on the rule UUID? (Treating it like a regular Access Policy rule)

0 Kudos
Danny
MVP Gold
MVP Gold

That's what I did. Filtering the rule UID works in SmartLog,

image.png

but doesn't return anything in SmartEvent.

image.png

the_rock
MVP Gold
MVP Gold

Never really played around with https inspection filters in smart event, but will check next week. Yes, UUID does work in regular log filters.

Best,
Andy
0 Kudos
Danny
MVP Gold
MVP Gold

I opened a SR with TAC. I'll update this thread when they find anything useful.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events