CheckPoint SmartView is a good tool for log reviews with its templates like Attacks Allowed by Policy. During IPS profile testing on the 1550 - you had to limit IPS protections in a special SMB profile with the older Embedded GAiA models while 1550 / R80.20 now has a TP policy like all GAiA GWs do - i also used SmartView. This gave me an odd encounter i would not have expected: hosts encountered an exploit attempt ! Have a look:
The 1550 FifteenFifty 😊 is managed by SMS7520 🙃 and set to send Security Logs and Syslog there. Seems not to be easy with Syslog, though:
Matthaeus 5:30:
And if thy right hand offend thee, cut it off, and cast it from thee 😎
CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist