- Products
- Learn
- Local User Groups
- Partners
-
More
Join Us for CPX 360
23-24 February 2021
Important certificate update to CloudGuard Controller, CME,
and Azure HA Security Gateways
How to Remediate Endpoint & VPN
Issues (in versions E81.10 or earlier)
IDC Spotlight -
Uplevel The SOC
Important! R80 and R80.10
End Of Support around the corner (May 2021)
Hi,
Recently implemented SCV to check if VPN user's computers are domain joined.
This is working and non-compliant users get the warning message.
At the moment it is set to Allow and log.
The SCV Registry Monitor policy definition is also configured to log (send_log =alert).
The issue is I can't find where this is logged on SmartConsole (R80.30)
I know that the non-compliance is only logged once but I should still be able to see it.
It could be that I'm just filtering/querying the wrong thing.
In Endpoint compliance I don't see anything either.
Any suggestions?
Thanks
SCV is a little different than Endpoint Compliance though it serves the same function.
I would expect the logs to appear as part of VPN/Remote Access and not necessarily Endpoint.
add the same issues there . if user has already authenticated months ago, you must look for the first time event since it will never be logged again ... we are thinking on asking for a RFE to get each time the scv logs whatever the results.
We have configured SCV recently and we are facing the same issue. our smart console is on R80.30. FYI: we are seeing the logs on the "Endpoint Compliance blade"
Also, we are seeing user as default in the MLM for non-compliant users. Any way we can resolve this issue?
any suggestions?
About CheckMates
Learn Check Point
Advanced Learning
WELCOME TO THE FUTURE OF CYBER SECURITY