Hi,
I have searched from qradar and got similar logs as below. The only different item is "sequencenum", is this desired situation?
Any advice would be appreciated.
Best
Jasmin
LEEF:2.0|Check Point|Identity Awareness|1.0|Log In|devTime=devtime usrName=xxx cat=Identity Awareness action=Log In ifdir=inbound logid=logid loguid={aaa} origin=ip originsicname=zzz sequencenum=6 version=5 auth_method=User Authentication (Active Directory) auth_status=Successful Login client_name=Active Directory Query client_version=R81.10 domain_name=domain_name endpoint_ip=ip_address identity_src=AD Query identity_type=user snid=sn_id src=src src_user_group=src_user_group src_user_name=xxx
LEEF:2.0|Check Point|Identity Awareness|1.0|Log In|devTime=devtime usrName=xxx cat=Identity Awareness action=Log In ifdir=inbound logid=logid loguid={aaa} origin=ip originsicname=zzz sequencenum=7 version=5 auth_method=User Authentication (Active Directory) auth_status=Successful Login client_name=Active Directory Query client_version=R81.10 domain_name=domain_name endpoint_ip=ip_address identity_src=AD Query identity_type=user snid=sn_id src=src src_user_group=src_user_group src_user_name=xxx