- CheckMates
- :
- Products
- :
- Quantum
- :
- Threat Prevention
- :
- Re: Anti-Bot Correlated Logs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Anti-Bot Correlated Logs
When I filter on Blade:Anti-Bot all I see is this. When I open a log card I have no meaningful information. What is causing these logs?
Should I worry, or just ignore them?
If I should worry - why?
If I should ignore them - how do I stop them from happening in the first place?
- Labels:
-
Anti-Bot
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Have you managed to figure out the meaning of these logs?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Nope! I'd still like to though.
I'm upgrading this particular system later this week from R80.40 to R81.10 so I'll see if that makes any difference...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
My first impression is that these correlated logs were just showing anti-bot scanning statistics (Scan Hosts ...), but the presence of "CU (Correlation Unit) Rule" means that it has something to do with SmartEvent. Looks like a false positive, see here: sk105300: SmartEvent Server sends out email alerts for Anti-bot detection with no corresponding logs...
CET (Europe) Timezone Course Scheduled for July 1-2
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Were you able to fix this issue?
