- CheckMates
- :
- Products
- :
- Quantum
- :
- Management
- :
- R80.30 Log Query syntax - tcp(syn)
Options
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×
Sign in with your Check Point UserCenter/PartnerMap account to access more great content and get a chance to win some Apple AirPods! If you don't have an account, create one now for free!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
R80.30 Log Query syntax - tcp(syn)
Hi,
The log query tcp (syn) returns my out of state log entries. What I would like to know is how this filter works so I can use the same technique for other advance queries.
For example, in plain language: all out of state where TCP flags is not (FIN or RST)
I am using R80.30 SmartConsole. We don't have SmartEvent.
Thanks,
-Wes
1 Reply
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I'm not familiar with that syntax.
When I try it in demo mode, I get lots of drops that aren't "out of state."
However, if you do tcp(!syn) then you get drops that are "out of state."
I don't think the relevant log fields are fully indexed, thus it's not clear how you'd pull out the entries that are not FIN or RST.
When I try it in demo mode, I get lots of drops that aren't "out of state."
However, if you do tcp(!syn) then you get drops that are "out of state."
I don't think the relevant log fields are fully indexed, thus it's not clear how you'd pull out the entries that are not FIN or RST.
