- CheckMates
- :
- Products
- :
- Quantum
- :
- Management
- :
- smartevent correlation unit problem
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
smartevent correlation unit problem
Hi all, i've been configuring for an event on my smartevent server that detects when 10 address spoofing logs in 20 seconds. But i can't get daily notification mails for specified ip addresses as i want with this settings, am i missing something? thanks,
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
SmartEvent works with Session logs by default.
For regular rules, you can turn them into Session logs with: https://support.checkpoint.com/results/sk/sk150452
Not sure if you can do this with Anti-Spoofing since that’s a Connection log and there’s no explicit rule.
Might require checking with TAC.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Does evstop; evstart help at all?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The correlated event is generated and the issue is the email notification?
Can you share the automatic reaction you attached to the event?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
actually it correlates and sends automatic reaction via email when i install the event policy but never correlates and sends notification again even though it exceeds the treshold values
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Is it out of the box event or something new that you created?
