Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Alexander_Lario
Explorer

SmartEvent email notifications

I need to configure email notification when critical event is appeared in logs. An email alert must send to administrator mail box when certain IPS protection is appeared in logs. I configuring SmartEvent for this task. An email alert is added in "Objects" -> "Automatic Reactions". Now i configured an alert for certain Firewall blade log (when someone tryng to get access to port 443 of certain IP external IP address, screenshot in attach) and this alert is working.
I configured an alert for Action: Detect (IPS blade) but there is no result (screenshot in attach).

There is default entry in "Global Exclusions" (screenshot in attach).
When this record is disabled, notifications about different events that I do not need are sends to my email address.

0 Kudos
6 Replies
PhoneBoy
Admin
Admin

FYI you can insert graphics inline (not as attachments).

Makes it easier to follow.

First off can you confirm version/jumbo hotfix level?

Looks like R80.10 from screenshots.

Also, when you make said changes, did you push the Event policy?

This is required anytime changes are made.

I assume the default exclusion is there for a reason. Smiley Happy

0 Kudos
Alexander_Lario
Explorer

Thank you for your answer.

Smart Event 80.10 jumbo hotfix Take 70 

Security Management Server 80.10 jumbo hotfix Take 42.

Yes, i install policy on Smart Event after make changes.

Yes, i returned default exclusions to the initial state.

0 Kudos
PhoneBoy
Admin
Admin

Can you show a log or two that should have matched this?

(Feel free to mask sensitive data)

0 Kudos
Alexander_Lario
Explorer

Example notificatinon:

0 Kudos
PhoneBoy
Admin
Admin

I recommend having TAC take a look at this, because that should catch it.

Contact Support | Check Point Software 

0 Kudos
Hugo_vd_Kooij
Advisor

2 things I would like to add here.

  1. Make sure you use the latest Jumbo Hotfix for Smart Event. There is so much more fixed that is not explicitly listed in the fix list. (I had too many TAC cases on SmartEvent 😉
  2. Be aware that if email delivery becomes a problem it will result in some additional issues on SmartEvent. So make sure you don't have a spam filter getting in the way. (Valueable lesson from said TAC cases.)
<< We make miracles happen while you wait. The impossible jobs take just a wee bit longer. >>
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events