In This Section: |
SmartEvent uses filtered event views, called queries, to identify and show relevant events. Event window information, timelines, graphs and reports are based on queries that identify potentially dangerous events and event patterns. You use this information to adjust your Security Policies and protection settings in response to detected threats.
SmartEvent uses filtered event views, called queries, to define the events to view. Located in the Queries Tree, these queries filter and organize event data for display in the Events, Charts and Maps tabs. Queries are defined by filter properties and charts properties. Filter properties allow you to define what type of events to display and how they should be organized. Charts properties allow you to define how the filtered event data should be displayed in chart form.
SmartEvent provides a thorough set of predefined queries, which are appropriate for many scenarios.
Queries are organized by combinations of event properties, for example:
Direction is determined by the Internal Network settings.
SmartEvent gives you the flexibility to define custom queries that show the most relevant events and trends. Once you have defined custom queries, you can organize them into folders so that they are easy to find and use.
You can use your queries to:
You can work with queries in the Events, Timelines, Charts and Maps windows. See the Reports section to learn about procedures for working with report queries.
To change query filter properties:
Selected criteria show in the In Use list. Criteria not selected show in the Ignored list. You can enter text in the Search Fields box to highlight matching text strings in criteria fields.
The window type and data entry procedures are different for each criterion type. The default value is Any.
In this case, the criterion filter applies to the query, but the column does not show. By default, the Show option is selected for all criteria.
Note - If you clear the Show option for a criterion that does not have a filter applied, that criterion automatically moves to the Ignored list. This action is the same as using the Remove button. |
This shows events with the same field value under a collapsible summary line. This option works best when you select only one criteria field.
When enabled, the query shows a Filter window and the user must select or enter the filter value. This makes the query more dynamic, enabling the user to specify values each time the query is run.
To clear filter values from a query:
You can create a custom query from scratch in the Custom folder or based on an existing query.
To create a custom query based on the default query:
To create a custom query based on an existing query:
To change the way your custom query will display as a chart:
If you want to display on a Time axis using a pre-defined Time Resolution, choose the Time Resolution you want.
You can create custom folders to organize your custom queries, as well as subfolders nested within folders.
To create a custom folder:
When you create a new query, you can save it to this new folder by selecting it before selecting Save in the Save to Tree window.
The Events tab is the heart of SmartEvent.
These are the components of the Events tab:
The Events tab is an Event Log that shows events generated by a query. In addition, the Events tab contains the Query Tree, the Event Preview Pane and the Event Statistics Pane.
Double-click a query in the Query Tree to run that query. The results show in the Event Log. The top Events, Destinations, Sources and Users of the query results are displayed in the Event Statistics Pane, either as a chart or in a tallied list. The details of the selected event are displayed in the Event Preview Pane.
The SmartEvent Event Log can display up to 100,000 events. The events displayed are the result of a query having been run on the Event Database. To run a different query, double-click on a query in the Selector tree. The Event Log will display the events that match the criteria of the query.
The Event Log is where detected events can be filtered, sorted, grouped, sent for review and exported to a file to allow you to understand your network security status. Event details, such as Start and End Time, Event Name and Severity, are displayed in a grid. In the Status bar at the bottom of the SmartEvent client window, Number of records in view displays a count of new events. Refresh retrieves the data from the database according the active query filter.
The details of an event provide important specifics about the event, including type of event, origin, service, and number of connections. You can access event details by double-clicking the event or by displaying the Event Preview Pane.
Queries are built with certain default settings that can be changed directly in the Events tab to provide more specific or more comprehensive results.
After you run a query, you can right-click a column and define the filter parameters to filter the event data. This temporarily includes the filter in the active query and runs the query again against the database to return the matching values.
A green filter icon at the top of a column indicates that a filter is applied to that field. To save the new set of filters as a custom query, select Save from the File menu. To discard the filters that was not saved, run the query again.
To use filters with query results:
Running a query can return thousands of matching events. To help you organize the events that have already been returned by the query, click a column header to sort these events
To look for events with specified values, enter values in the Search field. When you search for multiple values, with commas that separate the values, the events that contain the search values return. But the values can be in all event fields. The search can be made case-sensitive or can search data that does not show in columns.
One of the most powerful ways to analyze event data is by grouping the data based on the specific columns using the Group By button on the toolbar. Here you can group the events by one or more columns and the Event Log shows the number of matching events in those groups, presented in descending order.
You can also specify the default grouping that a query should use by marking fields as Grouped in the Events Query Properties window.
The top line of each group in the Event Log shows a summary of the events that it contains. If you hover over a field in the top line, you can see details of what data that field contains in all of the events in the group.
To group events by one or more fields, perform one of the following:
Once you have already grouped by a column, you can add another column to use for grouping by right-clicking on the column in the Event Log you want to use for grouping events and select Add this Column to the Group.
To remove fields from the grouping, perform one of the following:
In some circumstances, event information can be used to show evidence of a security attack or vulnerability that needs to be resolved. For example, you may decide that another member of your security team should review an event as evidence of an attack. Also, reporting events to Check Point can help Check Point improve the IPS technology to detect new threats in an ever-changing security environment. From the Event Log, you can choose to send event details as an email using your default email client, or you can choose to send the event details to Check Point over a secure SSL connection.
To send an event using email:
A new email opens using your default email client and the event information is included in the body of the email.
To report an event to Check Point:
Only the event information will be sent to Check Point over a secure SSL connection. The data is kept confidential and Check Point only uses the information to improve IPS.
The Events tab in the SmartEvent client can contain thousands of events. Export the events into a text file to review or manipulate the data with external applications. For example, a spreadsheet or text editor.
To export events to a comma-delimited (csv) file:
To maintain a high level of security, organizations must install the latest security patches on network computers. Many of the security patches are designed to prevent threats from exploiting known vulnerabilities. If you are consistent with implementing software patches, your network computers will not be vulnerable to some of the attacks that are identified by SmartEvent. SmartEvent ClientInfo helps you determine whether an attack related to Microsoft software is likely to affect the target machine. If the target machine is patched, you can stop the events from being generated by choosing to exclude the target machine from the event definition or from the specific IPS protection.
SmartEvent ClientInfo connects to the computer whose IP address is listed in the event. After you enter credentials with administrator privileges on the target computer, SmartEvent ClientInfo reads the list of Microsoft patches installed on the computer as well as other information about the installed hardware and software. SmartEvent ClientInfo also retrieves the Microsoft Knowledge Base article related to the vulnerability reported in the event and checks to see if the patches listed in the article are installed on the target computer. If SmartEvent ClientInfo finds that the matching patch is installed, it is likely that the attack will have no effect on the target computer and you can choose to create an exception so that IPS or SmartEvent stops recognizing the attack as a threat.
Once the computer information is loaded in SmartEvent ClientInfo, you can perform the following functions:
Icon |
Action |
---|---|
Save the information in the active tab to a .csv file |
|
Enter new credentials for accessing the computer information |
|
|
Copy the contents of the selected cell |
|
Run Google.com search using the contents of the selected cell |
Search field |
Filter the contents of the active tab for rows containing the search text |
Filter the contents of the active tab for rows containing the KB number |
|
Connect to the specified IP address to gather the computer information |
To make sure that a computer is not vulnerable to an attack:
SmartEvent ClientInfo retrieves the software and hardware information from the target computer, as well as the details of the Knowledge Base article associated with the vulnerability identified in the event.
Based on this, you can decide to modify the associated IPS protection or event definitions to prevent these events from displaying in the future.
Click on the KB numbers specified to open the associated Knowledge Base articles. Review the recommended remediation steps, which may include installing a patch on the target computer.
Click on the KB number specified to open the associated Knowledge Base article. Review the recommended remediation steps, which may include installing a patch on the target computer.
Note - If SmartEvent ClientInfo finds that the patch in the KB article is not installed on the remote computer, it may indicate one of the following:
|
The Event Log is accompanied by charts displaying the Top Events, Top Sources, Top Destinations and Top Users for the active query. These statistics are automatically updated as filters are applied to the Event Log.
You can toggle between viewing the statistics as a chart or a list by clicking on the arrow in the top-right corner of each of the boxes and selecting Show Pie Chart.
You can filter in or out any value in the Event Statistics Pane to focus the query results on the data that is most important to you. Filtering in the Event Statistics Pane is also reflected in the Event Log, and clearing filters from the Event Statistics Pane clears all filters that have been applied to the query.
See the details of an event from the Preview Pane in the Events tab or by double-clicking on the event in the Event Log. The Event Details window has two tabs with different data:
These options are available from the Event Details window:
The Summary tab includes:
The Details tab includes:
The Browse Time feature keeps track of the total time that users are connected to different sites and applications. R76 and later Security Gateways calculate the cumulative connection time for each session and periodically updates this value until the session is closed.
Browse time is calculated as follows:
SmartEvent includes a many different tools to let you analyze events that occur in your environment. You can get access to these tools using one of the tabs in the SmartEvent GUI.
The SmartEvent Overview tab shows critical security status information for your environment. Its main focus is presenting a quick view of the recent events data using the Timeline View, Recent Critical Events, and Top tables and chart. These interactive sections report on the events based on the Time Frame setting to allow you to display event data from a specific latest period of time.
Double-click on data in any of the sections in the Overview tab to open the associated list of events so that you can continue investigating issues all the way down to the individual event level.
By default, the Overview tab includes these sections:
You can search, sort, filter and group events using the same methods as in the Events tab. Click the arrow to select a different query to show here.
How do I view the details of an event?
How do I search in the query results?
How do I filter the query results?
How do I sort the query results?
How do I send an event to Check Point or to an email recipient?
How do I export a list of events to a tab-delimited (csv) file?
Timelines let you see specified recent events in a linear format. The number of events is shown inside a circle at each defined time interval. The circle itself is color coded to show the severity of the different events.
Note - Because timeline circles use colors to show event severity, timelines for queries without filters (such as a query by source IP address) are identical to those of the All Events query. |
You can modify these timelines or add new timelines for predefined and custom queries. You can also rename timelines and move them up or down the in the window.
To add a new timeline:
You can now see the configured timelines and you can modify the Time Frame and Time Line Resolution to help you analyze the event data.
To modify an existing timeline:
The selected timeline now displays the event data based on the modified query.
Charts display query results in a graphical format which you can configure to divide the events data based in any event characteristic. You can then drill down into any segment of the chart to display a list of those events in a new Events window.
Event queries can be shown with a Time Axis or as a Pie Chart. The query’s chart properties define which type of chart will be shown by default but you can change the chart type to display at any time by selecting from the options in the upper-left corner.
Event Data Options
The following are settings that can be set from the Toolbar to change the event data that is displayed in the chart:
You can also set a particular chart to be displayed by default in the Charts tab by right-clicking on the query and selecting Run on Start.
Manage Options
The following are options that can be changed from the Toolbar to present the chart data in a more informative and appealing manner:
The following are elements of the chart display that can be changed by right-clicking on the chart to customize the presentation of the chart:
You can modify the display options for the data grid, legend box, axis labels or axis scales. Right-clicking any of the elements allows you to change the font, text color, display location and other graphical options.
To view a chart:
You can also open your chart in a new window by right-clicking the query and selecting Run in New Window. This allows you to keep multiple charts open at the same time.
Source and Destination information are frequently critical when determining the potential threat of traffic. Some companies need to block traffic from certain countries based on security, political, or legal reasons whereas other companies may see identifying traffic by country of origin or destination simply as a way to limit the traffic passing through the network.
In the Maps tab, SmartEvent presents source and destination countries for the active query on an interactive world map. Countries are color-coded to indicate levels of event activity. You can define the number of countries to include in the top tier of countries (Top N) and in the second tier of countries (Next Top N) to change how countries are grouped in the map.
By double-clicking on a country, you can drill-down to see a detailed list of events for that country. By default the map shows the results of the All Events query; however, you can populate the map with information from any of the available queries by double-clicking on a query in the Query Tree. You can also choose to view continents individually in order to see countries more clearly.
Statistics information about the active query is displayed below the interactive map. The five countries with the highest number of events matching the query filter are shown with the number of events for each, as well as the total number of countries matching the query.
Interact with the map using the following actions:
Moving the mouse over a tier in the Activity Level key will highlight the Countries in that tier.
In addition, in the bottom left corner of the map is a summary of event statistics which includes the number of events for the top 5 countries and the total number of countries with events.
Use the Reports tab to see, manage and generate reports that show a summary of events identified by SmartEvent. You can generate report for these supported blades:
Most configuration steps occur in the Policy tab. System components, such as SmartEvent Correlation Unit, are defined here, as well as lists of blocked IP addresses and other general settings.
But the main attraction of the Policy tab is the configuration of each type of event. Each type of event that SmartEvent can detect is listed here, and sorted into a number of main categories. Each event can be customized by altering the default thresholds and setting Automated Responses. Events can also be disabled by removing the check mark. The settings made here are what determine the SmartEvent Event Policy.
The Policy tab is composed of three sections:
Once the SmartEvent client begins displaying events, the following tasks should be performed:
Modifications to the Event Policy do not take effect until saved on the SmartEvent server and installed to the SmartEvent Correlation Unit.
To enable changes made to the Event Policy:
You can undo changes to the Event Policy, if they were not saved.
To undo changes: click File > Revert Changes.