- Products
- Learn
- Local User Groups
- Partners
- More
CheckMates Fifth Birthday
Celebrate with Us!
days
hours
minutes
seconds
Join the CHECKMATES Everywhere Competition
Submit your picture to win!
Check Point Proactive support
Free trial available for 90 Days!
As YOU DESERVE THE BEST SECURITY
Upgrade to our latest GA Jumbo
The 2022 MITRE Engenuity ATT&CK®
Evaluations Results Are In!
Now Available: SmartAwareness Security Training
Training Built to Educate and Engage
MITRE ATT&CK
Inside Check Point products!
CheckFlix!
All Videos In One Space
Hello guys,
I am trying to setup some SNMP traps as automatic reactions on R80.10 SmartEvent. It doesn't seem to work the same way as it did in R77.30.
Fields like [Source] and [Destination] have an array of sub-fields which can be seen when using a script to print it: Destination: (countryname: United States; IP: 216.58.222.98; repetitions: 1).
Thus, when the host has a public IP address it returns only the countryname in the trap.
Also, the field [Origin] always returns the IP as "0", but I could really work with the second sub-field "hostname":
Origin: (IP: 0; hostname: SMS; repetitions: 1)
Is it possible to put these sub-fields in the trap using some variation of the notation [<field>]?
The alternative would be to create a script to filter the event output and send these traps, but I'd rather not have to install scripts every time I need to set these up.
Hi Pedro,
did you ever get anywhere with this? I have the same requirement...
Thanks!
Luke
Hello Luke,
No, I never solved this. I am currently experimenting with a third party SIEM, but it would be great to make this work correctly with SmartEvent.
Kfir Dadosh any thoughts on this one?
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY