- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi,
I have searched from qradar and got similar logs as below. The only different item is "sequencenum", is this desired situation?
Any advice would be appreciated.
Best
Jasmin
LEEF:2.0|Check Point|Identity Awareness|1.0|Log In|devTime=devtime usrName=xxx cat=Identity Awareness action=Log In ifdir=inbound logid=logid loguid={aaa} origin=ip originsicname=zzz sequencenum=6 version=5 auth_method=User Authentication (Active Directory) auth_status=Successful Login client_name=Active Directory Query client_version=R81.10 domain_name=domain_name endpoint_ip=ip_address identity_src=AD Query identity_type=user snid=sn_id src=src src_user_group=src_user_group src_user_name=xxx
LEEF:2.0|Check Point|Identity Awareness|1.0|Log In|devTime=devtime usrName=xxx cat=Identity Awareness action=Log In ifdir=inbound logid=logid loguid={aaa} origin=ip originsicname=zzz sequencenum=7 version=5 auth_method=User Authentication (Active Directory) auth_status=Successful Login client_name=Active Directory Query client_version=R81.10 domain_name=domain_name endpoint_ip=ip_address identity_src=AD Query identity_type=user snid=sn_id src=src src_user_group=src_user_group src_user_name=xxx
Two logs for the same event that close to each other doesn't seem correct.
Best to check this with TAC: https://help.checkpoint.com
Is the issue you’re seeing multiple logs for what appears to be the same event?
How far apart are the logs and how many “duplicates” appear?
We do send multiple logs via Log Exporter for the same session (every 10 minutes or so).
This is probably expected behavior.
Hi,
Thanks for your answer. There are two events for login and logout with the same devtime. (not every 10 minutes)
Best
Jasmin
Two logs for the same event that close to each other doesn't seem correct.
Best to check this with TAC: https://help.checkpoint.com
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 4 | |
| 3 | |
| 2 | |
| 2 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY