Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
okatsladz454
Contributor
Jump to solution

The src_country and dst_country fields

Good afternoon.

In the Threat Prevention logs fields of the demo stand (the one that can be opened when opening Smartconsole) I see two specific fields:

1. Source Country
2. Destination Country

Which display the source/destination country of the IP address, respectively. (screenshoot demo.png)

 

However, I do not see these fields on my stand, there is no display in the traffic section. (screenshoot mine.png)

Please tell me how to enable the display of data from two fields in smartlog and is it possible to export this through cp log exporter on log collector?

0 Kudos
1 Solution

Accepted Solutions
Duane_Toler
Advisor

The IP2Country mapping happens on the gateway.  The association between countries and flags happens on the management.

 

Check SK92823 to update the GeoIP info manually.  Be sure to install policy afterwards... just in case.If this doesn't help, then a call to TAC may be your next best thing.  There are a few odd complexities that can be involved, including the AutoUpdater service not functioning correctly. Although, it could be as simple as a policy error, too.

 

I can't remember for certain if you'll need to have the Geo Protection policy enabled, but I'm mostly certain you do.  I have one enabled on all of my customers, and theirs works; but causation != causality, tho.

 

View solution in original post

(1)
12 Replies
Duane_Toler
Advisor

Make sure the ip2country download and mapping is taking place correctly. 

https://support.checkpoint.com/results/sk/sk120261

https://support.checkpoint.com/results/sk/sk79360

https://support.checkpoint.com/results/sk/sk94364

Be sure to verify your software subscription and license contracts are in order so that the automatic download can take place correctly.

okatsladz454
Contributor

Good weekend, thanks for your help. 

 

Don t see this file on GW at all, should i add it or check the SMS too?

 

 

 

0 Kudos
Duane_Toler
Advisor

The IP2Country mapping happens on the gateway.  The association between countries and flags happens on the management.

 

Check SK92823 to update the GeoIP info manually.  Be sure to install policy afterwards... just in case.If this doesn't help, then a call to TAC may be your next best thing.  There are a few odd complexities that can be involved, including the AutoUpdater service not functioning correctly. Although, it could be as simple as a policy error, too.

 

I can't remember for certain if you'll need to have the Geo Protection policy enabled, but I'm mostly certain you do.  I have one enabled on all of my customers, and theirs works; but causation != causality, tho.

 

(1)
okatsladz454
Contributor

Good morning. 

 

It had no effect on logs, still i don t see source and destination country fields: 

 

 

version 81.20 last take

 

 

 

0 Kudos
okatsladz454
Contributor

IT probably help me 

I see the fiels at my syslogserver 

Thank you very much! 

 

 

 

the_rock
Legend
Legend

Good job!

0 Kudos
Duane_Toler
Advisor

Excellent!  Just to be certain, did you enable to Geo Protection policy as well?  Or just update ip2country info from the SK article?

0 Kudos
the_rock
Legend
Legend

Agree with @Duane_Toler 

0 Kudos
the_rock
Legend
Legend

Are you able to search by say basic filter src_country:CN for China, as an example.

Andy

0 Kudos
okatsladz454
Contributor

Good evening.

Nope. Tried to use the:

1) src_country:CN 

2)src_country:China

3)src_country:china

4) src_country:People's Republic of China

and other options 

 

but still nothing 

 

1.jpg

2.jpg

 

0 Kudos
the_rock
Legend
Legend

Does it work for any other country?

Andy

0 Kudos
okatsladz454
Contributor

Good morning. 

No, it doesn t work for other country:

 

 

 

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events