Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Blason_R
Leader
Leader

Wondering if Policy Push can be alerted with the help of Skyline?

Hi Folks,

I am now good with Skyline alerts and have created a bunch of of those. Now I am wondering if policy pushed can be tracked and alerted with the help of opentelemetry or skyline?

Here is my query

(firewall_policy_time{host_name="Firewall", environment=~"Default", service_namespace="vs_id_0"}>100000)*1000

 

@Arik_Ovtracht - Can you please help?

 

TIA

Blason R

Thanks and Regards,
Blason R
CCSA,CCSE,CCCS
4 Replies
Elad_Chomsky
Employee
Employee

Hi @Blason_R ,

Try to experiment by doing something like this - 

(firewall_policy_time { host_name="Firewall"environment=~"Default"service_namespace="vs_id_0"} - firewall_policy_time{ host_name="Firewall"environment=~"Default"service_namespace="vs_id_0"} offset 15s) != bool 0
 
I used the offset instruction to get the last sample  ( 15s before ), then I compared the difference and checked if it is not 0.
In general the use case that you are referring to is classified as an 'event'. 
We are aiming to support events in the future, and it is currently part of our plans and roadmap.
0 Kudos
Blason_R
Leader
Leader

That is great and thanks for the input. However that query is not working for me.

Thanks and Regards,
Blason R
CCSA,CCSE,CCCS
0 Kudos
Blason_R
Leader
Leader

This is correct and then I can define Last of  $A != 0 

(firewall_policy_time { host_name="Firewall", environment=~"Default", service_namespace="vs_id_0" } - firewall_policy_time { host_name="Firewall", environment=~"Default", service_namespace="vs_id_0"} offset 15s)

Thanks and Regards,
Blason R
CCSA,CCSE,CCCS
0 Kudos
Elad_Chomsky
Employee
Employee

I have fixed the query on the original post, please retry - 

1 - policy has changed

0 - policy has not changed

Please contact me privately on eladch@checkpoint.com, so I can try to assist you with any further issues.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events