- CheckMates
- :
- Products
- :
- Quantum
- :
- Threat Prevention
- :
- Filtering out IPS alerts with PCAP
Options
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×
Sign in with your Check Point UserCenter/PartnerMap account to access more great content and get a chance to win some Apple AirPods! If you don't have an account, create one now for free!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Filtering out IPS alerts with PCAP
Hi
Wondering if there is any way to filter out IPS alerts which have a pcap file attached in SmartLog? If not, is there any other way to see the pcap files, where are they stored? I'm running version r80.30 on the log server.
Best Regards
Norbert
1 Reply
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
For R80.10+ gateways, IPS packet captures are automatically transferred to the Log Server (usually the SMS or CMA) and
stored in the $FWDIR/log/forensics and /var/spool/mail directories.
Attend my Gateway Performance Optimization R81.20 course
CET (Europe) Timezone Course Scheduled for July 1-2
CET (Europe) Timezone Course Scheduled for July 1-2
