Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
eivanov
Explorer
Jump to solution

It is necessary to select certain SNMP traps when working internal_snmp_trap

Hi all!
There is a need to selectively send internal_snmp_trap IPS events with only critical importance (severity Hight and critical) and awareness level High (confidence)

Currently Checkpoint sends all events to Zabbix Server

 

2_IPS_3.png

Thank you!

0 Kudos
1 Solution

Accepted Solutions
PhoneBoy
Admin
Admin

To be selective about what you send to Zabbix, you'll probably need to write a script to send only events you care about.
This script will need to exist on the management server.

View solution in original post

3 Replies
PhoneBoy
Admin
Admin

To be selective about what you send to Zabbix, you'll probably need to write a script to send only events you care about.
This script will need to exist on the management server.

eivanov
Explorer

Thank you very much for your answer. Is there an example of creating such a script or

a document describing how to do this? 

 

0 Kudos
PhoneBoy
Admin
Admin

The start of your script will be something like:

#!/bin/bash
event=`</dev/stdin`

You will have to parse the event variable based on your specific requirements and send the appropriate SNMP trap using the CLI command fwm snmp_trap.
See: https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_CLI_ReferenceGuide/Content/T... 

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events