Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Norbert_Anderss
Explorer

Filtering out IPS alerts with PCAP

Hi

Wondering if there is any way to filter out IPS alerts which have a pcap file attached in SmartLog? If not, is there any other way to see the pcap files, where are they stored? I'm running version r80.30 on the log server.
Best Regards
Norbert

0 Kudos
1 Reply
Timothy_Hall
Champion Champion
Champion

For R80.10+ gateways, IPS packet captures are automatically transferred to the Log Server (usually the SMS or CMA) and
stored in the $FWDIR/log/forensics and /var/spool/mail directories.

Gateway Performance Optimization R81.20 Course
now available at maxpowerfirewalls.com
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    Tue 23 Apr 2024 @ 11:00 AM (EDT)

    East US: What's New in R82

    Thu 25 Apr 2024 @ 11:00 AM (SGT)

    APAC: CPX 2024 Recap

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Thu 02 May 2024 @ 11:00 AM (SGT)

    APAC: What's new in R82

    Tue 23 Apr 2024 @ 11:00 AM (EDT)

    East US: What's New in R82

    Thu 25 Apr 2024 @ 11:00 AM (SGT)

    APAC: CPX 2024 Recap

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Thu 02 May 2024 @ 11:00 AM (SGT)

    APAC: What's new in R82
    CheckMates Events