Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
AngeloP
Participant

Failed getting the incident file from the gateway. It may be expired

Hi,

 

I noticed that in SmartConsole while analyzing logs from the IPS module that sometimes pcap's are not available for analysis, with the following error like in the attached image:

Failed getting the incident file from the gateway. It may be expired

 

i found the log file for the specific event and it is present on the gateway, the alert itself shows the pcap is present and has a unique id (actual filename on the gateway) but for some reason it can't pull it on smartconsole to display for analysis.

 

worth noting that only some alerts show the "failed getting the incident file from the gateway", other display their pcap's just fine but i didn't notice some specific pattern, as in the time of alert has no meaning and older alerts are able to display pcaps while some newer alerts can't. What could cause this?

 

 

 

 

 

 

 
4 Replies
ItsTheFirewall
Explorer

Any feedback on this. We are also seeing the same.

0 Kudos
the_rock
Legend
Legend

Based on below, seems there is a hotfix for it you need to ask TAC for.

Andy

https://community.checkpoint.com/t5/Threat-Prevention/Cannot-open-packet-capture-files-in-ips-log/td...

0 Kudos
ItsTheFirewall
Explorer

Thank you  

0 Kudos
the_rock
Legend
Legend

This was back in 2020, lots has changed since then : - ).

But, I would still inquire about it, you can even send them the link once you open the case, thats what I always do anyway, its a good reference.

Andy

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events