Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
jcallahan
Explorer

SmartEvent alerting on logs that don't match filter?

I have defined some events in SmartEvent to get alerted when IPS sees traffic that matches a protection that is still staged and not prevented. However, I am getting alerted on traffic that appears to have been prevented by the blade. That does not match what I put in the filter. Any insight on why the traffic is generating an event? I have attached a sample traffic and my defined event.

 

 

0 Kudos
3 Replies
PhoneBoy
Admin
Admin

Are both of those IPS events generating alerts?
We would have to see the log card on both to comment further (mask sensitive data if required).

0 Kudos
jcallahan
Explorer

I believe just the correlated log is the one firing off the alert. It makes sense to me that the severity is 4 and the action is blank, so therefore it is NOT prevent. That would make it match the criteria that SmartEvent is looking for. If that's the case, I might have to filter out correlated logs.

0 Kudos
PhoneBoy
Admin
Admin

That also makes sense to me as well. 

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    Tue 20 May 2025 @ 11:30 AM (PDT)

    Las Vegas: Check Point Hybrid Mesh

    Wed 21 May 2025 @ 11:30 AM (MST)

    Tempe, AZ: Check Point Hybrid Mesh

    Tue 03 Jun 2025 @ 06:00 PM (EDT)

    Montreal: CPX Recap

    Tue 10 Jun 2025 @ 06:00 PM (EDT)

    Quebec City: CPX Recap
    CheckMates Events