Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
AkosBakos
Advisor
Jump to solution

IPS events grouping in SmartLog

Hi CheckMates,

I have a simple question.

How can I set (can it be set at all?) the grouping the IPS events in SmartLog? Now The SmartLog was joking me, and collected the log into a group (this were IPS Prevent logs) so I couldn't find that, the traffic is prevented for the first sight.

This is a small thing, but really annoying.

Any tips are welcome

Akos

----------------
\m/_(>_<)_\m/
0 Kudos
1 Solution

Accepted Solutions
Timothy_Hall
Legend Legend
Legend

I'm assuming you are referring to Threat Prevention Log Suppression, and not SmartEvent's correlation of multiple logs into events.

Bottom line is that yes, Log Suppression can be disabled on the gateway by changing a kernel variable.  But be warned that this can substantially increase the number of logs sent to your SMS/Log Server.  See my 2022 Max Gander CPX Speech for a detailed discussion of Log Suppression and its varying suppression intervals, and these: 

sk108423: IPS generates Alerts instead of Logs in R77.30 and lower

sk115876: Some fields are missing from IPS or Threat Prevention logs

 

Gateway Performance Optimization R81.20 Course
now available at maxpowerfirewalls.com

View solution in original post

2 Replies
Timothy_Hall
Legend Legend
Legend

I'm assuming you are referring to Threat Prevention Log Suppression, and not SmartEvent's correlation of multiple logs into events.

Bottom line is that yes, Log Suppression can be disabled on the gateway by changing a kernel variable.  But be warned that this can substantially increase the number of logs sent to your SMS/Log Server.  See my 2022 Max Gander CPX Speech for a detailed discussion of Log Suppression and its varying suppression intervals, and these: 

sk108423: IPS generates Alerts instead of Logs in R77.30 and lower

sk115876: Some fields are missing from IPS or Threat Prevention logs

 

Gateway Performance Optimization R81.20 Course
now available at maxpowerfirewalls.com
AkosBakos
Advisor

Exactly! Thanks for the clarification.

Now, I think I should live together with this feature 🙂

Akos

----------------
\m/_(>_<)_\m/
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events