- Products
- Learn
- Local User Groups
- Partners
- More
Check Point Jump-Start Online Training
Now Available on CheckMates for Beginners!
Welcome to Maestro Masters!
Talk to Masters, Engage with Masters, Be a Maestro Master!
ZTNA Buyer’s Guide
Zero Trust essentials for your most valuable assets
The SMB Cyber Master
Boost your knowledge on Quantum Spark SMB gateways!
Check Point's Cyber Park is Now Open
Let the Games Begin!
As YOU DESERVE THE BEST SECURITY
Upgrade to our latest GA Jumbo
CheckFlix!
All Videos In One Space
Hi,
is it possible to control the severity of snort rules imported into CheckPoint Threat Preventions? For example using priority keyword or by category, or is it always severity:High for snort rules in checkpoint?
Thank you
Your question was answered in my IPS/AV/ABOT Immersion video series; the answer is yes you can change them but it requires the use of GUIDBedit, and future SNORT import operations for the same signature will set the three rating criteria back to their default values. You really should be using the newer Custom Threat Indicators feature instead which is much more flexible and easy to work with.
Thank you, so basically there's absolutely no way you can control severity of any protections in checkpoint smartdefense? That's a useful feature if say you have a rule in your SIEM to generate offenses above severity 2 or 3 based on threat prevention logs from checkpoint, and use a lower severity for testing signatures and not generate SIEM offenses. Or even change a specific Checkpoint signature to lower severity, to not have it generate offenses but still keep the logs. The flexibility just keeps being underwhelming, i keep hearing "no you can't do that here" at everything i ask.
Your question was answered in my IPS/AV/ABOT Immersion video series; the answer is yes you can change them but it requires the use of GUIDBedit, and future SNORT import operations for the same signature will set the three rating criteria back to their default values. You really should be using the newer Custom Threat Indicators feature instead which is much more flexible and easy to work with.
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY