Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
portfast
Explorer

smartevent correlation unit problem

Hi all, i've been configuring for an event on my smartevent server that detects when 10 address spoofing logs in 20 seconds. But i can't get daily notification mails for specified ip addresses as i want with this settings, am i missing something? thanks,

 

smartevent.png

0 Kudos
2 Replies
PhoneBoy
Admin
Admin

SmartEvent works with Session logs by default.
For regular rules, you can turn them into Session logs with: https://support.checkpoint.com/results/sk/sk150452

Not sure if you can do this with Anti-Spoofing since that’s a Connection log and there’s no explicit rule.
Might require checking with TAC.

0 Kudos
the_rock
Legend
Legend

Does evstop; evstart help at all?

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events