Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Daniel_Kavan
Advisor
Advisor

smartevent alerts

 

RE: credential guessing

So, I have smart event set to 

1. send me an email

2. block source for a day

 

I noticed that I received the email but the source was NOT blocked for the day.  Which was good since it was a legitimate user, but curious if other users had a similar experience.

I didn't see any SAM blocks from that source IP in smartevent just the email.

0 Kudos
6 Replies
the_rock
Legend
Legend

Any other logs about it?

Daniel_Kavan
Advisor
Advisor

Good idea!

Failed to add the following dynamic (SAM) rule: Action: Reject , Source IP: xx.63.x.xxx, Expiration: 86400 seconds, Track: Alert, Additional Info: sam file size exceeded

0 Kudos
the_rock
Legend
Legend

Got a screenshot of it?

Andy

0 Kudos
Daniel_Kavan
Advisor
Advisor

failed to SAM drop for dayfailed to SAM drop for day

0 Kudos
the_rock
Legend
Legend

What Phoneboy sent sounds like a good solution for that.

Andy

0 Kudos
PhoneBoy
Admin
Admin

There are a limited number of SAM rules supported.
The SAM database will need be purged.
Go to the relevant gateway object and check the "Purge" box.
Push policy.
Go back to the object and disable the "Purge" box.
Push policy again.
Or you can leave the auto-purge on and set a value for it (5mb was the last maximum I saw for this).

image.png

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events