- CheckMates
- :
- Products
- :
- Quantum
- :
- Management
- :
- SmartEvent User Defined Events
Options
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×
Sign in with your Check Point UserCenter/PartnerMap account to access more great content and get a chance to win some Apple AirPods! If you don't have an account, create one now for free!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
SmartEvent User Defined Events
Hi All,
I am working on creating a User Defined Event for long standing DNS connections (potential exfil operations)
When creating the event, I don't get an option to define login for an "Over" amount of duration like >200 seconds as an example.
I cannot seem to get an event to generate when testing, the times can only be equals, being an exact number.
Has anyone had any success with creating a user defined event for connections over a specific duration? How did you do it? I also want to do the same for high bandwidth sessions and I am also stuck with equals and no over/under.
1 Reply
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
My understanding is that these are thresholds, not exact limits.
Which means specifying 200 seconds should have worked.
You may need to check this with TAC.
