- Products
- Learn
- Local User Groups
- Partners
- More
Check Point Jump-Start Online Training
Now Available on CheckMates for Beginners!
Why do Hackers Love IoT Devices so Much?
Join our TechTalk on Aug 17, at 5PM CET | 11AM EST
Welcome to Maestro Masters!
Talk to Masters, Engage with Masters, Be a Maestro Master!
ZTNA Buyer’s Guide
Zero Trust essentials for your most valuable assets
The SMB Cyber Master
Boost your knowledge on Quantum Spark SMB gateways!
As YOU DESERVE THE BEST SECURITY
Upgrade to our latest GA Jumbo
CheckFlix!
All Videos In One Space
When I filter on Blade:Anti-Bot all I see is this. When I open a log card I have no meaningful information. What is causing these logs?
Should I worry, or just ignore them?
If I should worry - why?
If I should ignore them - how do I stop them from happening in the first place?
Have you managed to figure out the meaning of these logs?
Nope! I'd still like to though.
I'm upgrading this particular system later this week from R80.40 to R81.10 so I'll see if that makes any difference...
My first impression is that these correlated logs were just showing anti-bot scanning statistics (Scan Hosts ...), but the presence of "CU (Correlation Unit) Rule" means that it has something to do with SmartEvent. Looks like a false positive, see here: sk105300: SmartEvent Server sends out email alerts for Anti-bot detection with no corresponding logs...
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY