2010-10-20
09:40 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
CheckPoint Firewall Log - Rule Name field
We need to query/report CheckPoint firewall logs and use the rulename field to identify the traffic hitting each rule. The rulename filed is not being populated in enVision. We don't want to rely on the rule id field because the rule number can change as firewall rules are added and deleted. Does anyone knows if enVision is collecting/parsing the rulename field for CheckPoint devices?
1 Reply
2010-10-31
11:41 PM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
The October ESU will add support for both the rule name and rule UID fields to the Content 2.0 version of CheckPoint.
