- CheckMates
- :
- Products
- :
- Quantum
- :
- Threat Prevention
- :
- Threat Indicators
Options
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×
Sign in with your Check Point UserCenter/PartnerMap account to access more great content and get a chance to win some Apple AirPods! If you don't have an account, create one now for free!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Threat Indicators
We added the Threat Indicator to R80.40 through the SmartConsole, by exporting a CSV file.
How do we find information through ssh GAIA about which Indicators are currently installed on the cluster? We have tried using the ioc_feeds show command, but we get the output:
There are no existing feeds
Total number of feeds: 0
Active feeds: 0
Searching through the file we messed up through the SmartConsole didn't help either. Please help me find our Indicator in Gaia so that we can be sure that the Indicators have installed on the cluster.
How do we find information through ssh GAIA about which Indicators are currently installed on the cluster? We have tried using the ioc_feeds show command, but we get the output:
There are no existing feeds
Total number of feeds: 0
Active feeds: 0
Searching through the file we messed up through the SmartConsole didn't help either. Please help me find our Indicator in Gaia so that we can be sure that the Indicators have installed on the cluster.
2 Replies
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I don't know an easy way to dump the list of patterns/signatures being enforced by the gateway, but you could try giving your custom indicator a unique name, install policy to the gateway, then try to grep for the name of the custom indicator out on the gateway where it has its complied policy cached like this:
grep -i indicatorname $FWDIR/state/local/FW1/*
grep -i indicatorname $FWDIR/state/local/AMW/*
Attend my Gateway Performance Optimization R81.20 course
CET (Europe) Timezone Course Scheduled for July 1-2
CET (Europe) Timezone Course Scheduled for July 1-2
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Is it possible to delete a certain line from an imported CSV file in R80.40?
Or is it necessary to delete the whole added file and then attach a new one, where a certain line will be deleted?
For example, delete the first line without deleting the whole file?
