80.10 and SmartLog queries

Question asked by Rick Isbell on Dec 18, 2017
Latest reply on Dec 24, 2017 by Yaakov Ohayon

I have been using CheckPoint firewalls for about 6 years and since day 1 have thought that they 'did it right' for both the firewall admin and the security analyst.  However, the lack of flexibility to get data, reports, and alerts out of the SmartLog and SmartEvent makes we want to rip it out and put in a Linksys with Kiwi syslogging.


For example, why does (NOT protection_type:"blockbycountries") give me all logs except for geo-location ones, and (protection_type:"blockbycountries") returns nothing?


I feel that 80.10 is a SERIOUS step backwards in regards to logging, monitoring, & event analysis.  I previously used R75.40, R77.30, and even NGSE and was able to create a detailed view of the inbound and outbound traffic on a daily basis.  Now, the exported log output shows a handful of columns whereas the older versions had dozens.


If I am missing something can someone please shed some light on it?