- CheckMates
- :
- Products
- :
- Quantum
- :
- Management
- :
- Re: smartevent alerts
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
smartevent alerts
RE: credential guessing
So, I have smart event set to
1. send me an email
2. block source for a day
I noticed that I received the email but the source was NOT blocked for the day. Which was good since it was a legitimate user, but curious if other users had a similar experience.
I didn't see any SAM blocks from that source IP in smartevent just the email.
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
There are a limited number of SAM rules supported.
The SAM database will need be purged.
Go to the relevant gateway object and check the "Purge" box.
Push policy.
Go back to the object and disable the "Purge" box.
Push policy again.
Or you can leave the auto-purge on and set a value for it (5mb was the last maximum I saw for this).
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Any other logs about it?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Good idea!
Failed to add the following dynamic (SAM) rule: Action: Reject , Source IP: xx.63.x.xxx, Expiration: 86400 seconds, Track: Alert, Additional Info: sam file size exceeded
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Got a screenshot of it?
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
failed to SAM drop for day
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
What Phoneboy sent sounds like a good solution for that.
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
There are a limited number of SAM rules supported.
The SAM database will need be purged.
Go to the relevant gateway object and check the "Purge" box.
Push policy.
Go back to the object and disable the "Purge" box.
Push policy again.
Or you can leave the auto-purge on and set a value for it (5mb was the last maximum I saw for this).
