- CheckMates
- :
- Products
- :
- Quantum
- :
- Management
- :
- Searching for logs by country
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Searching for logs by country
Hi,
I'm trying to do some queries on the traffic to outbound to other countries. I can't seem to do a query string that would show traffic by country. Actually what i'm trying to do is look at the traffic that's NOT in the US. We're looking at enhancing our GeoProtect policy, but i'm not able to figure out how to do so.
One thing i've done is turned on Debug for SmartLog and I can see all the fields in the xml format and the dst_country is always coming up as "other". Is this an issue or this something that can be fixed so this field can be used in searches? Or is there a better way to search for traffic going to other countries and omit the ones I don't want to see?
Jonathan
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
We don’t log the actual country, if I recall.
What you see in SmartView is generated from a local IP to Country mapping.
Your best bet is to create an ordered layer that will generate a log if not in the US (or whatever countries you wish to exclude).
It should be after all your other layers.
You can then see what log entries match that rule.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
To add to what PhoneBoy wrote, you can create rules or Layers with Updatable Objects using relevant countries and then filter the matching rules in the Logs:
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
So then would I need to know the IP range for the US and omit that in the destination? or rather put that and do a negate cell to omit it?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You can do what @Sorin_Gogean suggested, but also below link has the actual good example.
Cheers,
Andy
https://community.checkpoint.com/t5/Management/Filter-Logs-by-geo-location/td-p/73745
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You can search the logs based on country like in the screenshots:
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
This also searches both the source and the destination fields, but there seems to be a maximum length for the country name: If I search for "United States Of America" or "United States Of" I get nothing, but using "United States" gets results.
