Hello All...
I'm trying to set up an email alert for every IPS log with action prevent and/or severity critical.
After proper capturing I whish to block the source for, say, 8 hrs. BUT, as hard as I tried, I cannot capture severity field!
When I try to use Severity Equal to Critical it never captures the event... Tried other fields, such as attack ID or attack name and I alway got no reaction as well...
Versions I have are R80.30 for SmartConsole and SmartEvent.
So, Detailing...
Read somewhere around here I should have "Generic IPS Event" active. I set it, and I set a email reaction.
In fact, only after this ticked I started capturing events but never received an email for this "Generic IPS Event".
![Geeneric.png Geeneric.png](https://community.checkpoint.com/t5/image/serverpage/image-id/11354i6AD5EFDC36B769AB/image-dimensions/698x239?v=v2)
User defined event, "IPSActionEvent" is defined as follows and seems to work 🙂
Product I use from list is IPS Software Blade...
![event1.PNG event1.PNG](https://community.checkpoint.com/t5/image/serverpage/image-id/11351i30E640CB28573688/image-size/large?v=v2&px=999)
I got emails for this "User defined Event | IPSActionEvent" BUT only when I place action equal to prevent.
Here snaphots from logs...
![correlates.PNG correlates.PNG](https://community.checkpoint.com/t5/image/serverpage/image-id/11355i7D69FD389C2FC549/image-dimensions/698x453?v=v2)
Seemed ok until now BUT 😞 When I try to use Severity Equal to Critical it never captures the event...
Tried other field, as attack ID or attack name and I alway got no reaction.
![Event2.PNG Event2.PNG](https://community.checkpoint.com/t5/image/serverpage/image-id/11352i62B96BEC71A0403E/image-size/large?v=v2&px=999)
I wonder why?
Any help is welcomed
Best Regards,
Paulo Balau