- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Up front:
I read that "The Description field is not currently indexed" - that might be the answer to my question - but I still do not have a working workaround..
My question:
I know I have hits on my 80.30 firewall ( Appliance model 5200 running R80.30 take 200 Last updated on: Mon Jan 6 14:01 2020) from the europol DNS scanner from "*.shadowserver.org" but when I search for it by name and as source (with the src:* before the domain name) I get 0 hits.
Img1
To see if the (.) dot was needed I added it after the star so it said "src:*." and searched again but still no hits..
Img5
If I alter the search to not include the star (*) and dot (.) and just search for the domaine i get 2 hits.. (indicating that it had never been the source but have been the destination at some time) <-- that is also correct but i am missing all the log lines where it was the source...
Img2
Finally - If I instead search for the IP address that the server had at the given point in time it was logged I get MANY hits and can see in the description and source column that the name "shadowserver.org" is logged with the FQDN of scan-09h.shadowserver.org - that is odd (why was it then not found in the prior 2 searches i made ?)
Img3
Searching for the full name (not using *.) does give me the hits - but I would really like to get the info of all the hosts with the domaine .shadowserver.org that have hit my firewall
Img4
Now..
Can any one here tell me if I need to use another search terminology/syntax or if the 80.30 search function in logs is broken ?
Best regards
Keld Norman
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 16 | |
| 15 | |
| 7 | |
| 5 | |
| 5 | |
| 5 | |
| 4 | |
| 4 | |
| 4 | |
| 4 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY