Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Daniel_Kavan
MVP Gold
MVP Gold
Jump to solution

smartevent alerts

 

RE: credential guessing

So, I have smart event set to 

1. send me an email

2. block source for a day

 

I noticed that I received the email but the source was NOT blocked for the day.  Which was good since it was a legitimate user, but curious if other users had a similar experience.

I didn't see any SAM blocks from that source IP in smartevent just the email.

0 Kudos
1 Solution

Accepted Solutions
PhoneBoy
Admin
Admin

There are a limited number of SAM rules supported.
The SAM database will need be purged.
Go to the relevant gateway object and check the "Purge" box.
Push policy.
Go back to the object and disable the "Purge" box.
Push policy again.
Or you can leave the auto-purge on and set a value for it (5mb was the last maximum I saw for this).

image.png

View solution in original post

6 Replies
the_rock
MVP Gold
MVP Gold

Any other logs about it?

Best,
Andy
Daniel_Kavan
MVP Gold
MVP Gold

Good idea!

Failed to add the following dynamic (SAM) rule: Action: Reject , Source IP: xx.63.x.xxx, Expiration: 86400 seconds, Track: Alert, Additional Info: sam file size exceeded

0 Kudos
the_rock
MVP Gold
MVP Gold

Got a screenshot of it?

Andy

Best,
Andy
0 Kudos
Daniel_Kavan
MVP Gold
MVP Gold

failed to SAM drop for dayfailed to SAM drop for day

0 Kudos
the_rock
MVP Gold
MVP Gold

What Phoneboy sent sounds like a good solution for that.

Andy

Best,
Andy
0 Kudos
PhoneBoy
Admin
Admin

There are a limited number of SAM rules supported.
The SAM database will need be purged.
Go to the relevant gateway object and check the "Purge" box.
Push policy.
Go back to the object and disable the "Purge" box.
Push policy again.
Or you can leave the auto-purge on and set a value for it (5mb was the last maximum I saw for this).

image.png

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events