- CheckMates
- :
- Products
- :
- Quantum
- :
- Management
- :
- Re: Traffic visual presentation from logs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Traffic visual presentation from logs
Hello Team,
I have only one rule (accept all "clean-up") in the security policy.
We need granular policy above cleanup rule and to put cleanup action at the end to Drop.
Customer is "blind" to traffic, no requirments and specification.
Is there any of rule log analyzing without going manually through logs in smart console?
Any script to present traffic (IP's, ports, services,...) in HTML or similar?
It would save our lives 🙂
Thank You in advance.
- Labels:
-
Logging
-
Monitoring
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Such tools typically present your existing policy in a Web format.
Since yours is not yet defined there are two options that come to mind, engage PS to assist in performing log analysis.
You might also choose to investigate NDR to help gain some valuable insights.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Is smartevent enabled? Have you tried the predefined views and reports?
You could also enable app-control and url filtering to start getting insights above layer 4.
I'd also suggest, from a layer 4 perspective:
https://community.checkpoint.com/t5/General-Topics/Tip-of-the-Week-connstat-Utility/td-p/88570
Connstat analyses snapshots of the connections table.
And CPmonitor analyses traffic captures.
Juan
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello,
Smart Event is enabled. I tried with reports but it is not so relevant to catch all services in details.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You could try to use the views generated by the Monitoring blade (it needs to be enabled).
Go to - SmartConsole > Gateways & Servers > select the relevant Security Gateway > apply Monitor
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
