- Products
- Learn
- Local User Groups
- Partners
- More
CheckMates Fifth Birthday
Celebrate with Us!
days
hours
minutes
seconds
Join the CHECKMATES Everywhere Competition
Submit your picture to win!
Check Point Proactive support
Free trial available for 90 Days!
As YOU DESERVE THE BEST SECURITY
Upgrade to our latest GA Jumbo
The 2022 MITRE Engenuity ATT&CK®
Evaluations Results Are In!
Now Available: SmartAwareness Security Training
Training Built to Educate and Engage
MITRE ATT&CK
Inside Check Point products!
CheckFlix!
All Videos In One Space
I'm trying to be able to identify via LEA when an inline rule is being hit. Currently LEA is only returning the rule uid of the Parent rule.
For example if you had a policy that looked something like:
Rule 1 Action: Inline_Layer_1
Rule 1.1
Rule 1.2
Rule 1.3
I'd consider Rule 1 the parent rule and Rule 1.1, 1.2, 1.3 the child rules.
Let's say that Rule 1 and Rule 1.1 were hit.
Currently via LEA we are getting the rule uid of Rule 1. However we're not getting the rule uid of Rule 1.1. So we can tell how many hits an entire Inline policy is getting (which equals the number of hits of Rule 1), however we're unable to tell via LEA which of the Inline rules are being utilized.
Since you have to tell LEA what fields to include in the data it sends, what identifier do we need to utilize to get LEA to send the rule uid of a child inline rule when hit.
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY