- Products
- Learn
- Local User Groups
- Partners
- More
Welcome to Maestro Masters!
Talk to Masters, Engage with Masters, Be a Maestro Master!
Join our TechTalk: Malware 2021 to Present Day
Building a Preventative Cyber Program
Be a CloudMate!
Check out our cloud security exclusive space!
Check Point's Cyber Park is Now Open
Let the Games Begin!
As YOU DESERVE THE BEST SECURITY
Upgrade to our latest GA Jumbo
CheckFlix!
All Videos In One Space
I'm trying to be able to identify via LEA when an inline rule is being hit. Currently LEA is only returning the rule uid of the Parent rule.
For example if you had a policy that looked something like:
Rule 1 Action: Inline_Layer_1
Rule 1.1
Rule 1.2
Rule 1.3
I'd consider Rule 1 the parent rule and Rule 1.1, 1.2, 1.3 the child rules.
Let's say that Rule 1 and Rule 1.1 were hit.
Currently via LEA we are getting the rule uid of Rule 1. However we're not getting the rule uid of Rule 1.1. So we can tell how many hits an entire Inline policy is getting (which equals the number of hits of Rule 1), however we're unable to tell via LEA which of the Inline rules are being utilized.
Since you have to tell LEA what fields to include in the data it sends, what identifier do we need to utilize to get LEA to send the rule uid of a child inline rule when hit.
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY