Exceptions
Exceptions allow an event Record of a security or network incident that is based on one or more logs, and on a customizable set of rules that are defined in the Event Policy. to be independently configured for the sources, destination, service and other parameters depending on the event type.
For example, if the event Scans > Port Scan from Internal Network is set to detect an event when 30 port scans occur within 60 seconds, you can also define that two port scans detected from host A within 10 seconds of each other is also an event.
To add an exception:
-
In SmartConsole
Check Point GUI application used to manage a Check Point environment - configure Security Policies, configure devices, monitor products and events, install updates, and so on., from the left navigation panel, click the Logs & Monitor view.
-
At the top, click + to open a new tab.
-
In the bottom section External Apps, click SmartEvent Settings & Policy.
-
In the section Apply the following exceptions to the event definition, click Add (on the right side, move the scrollbar down to see this section).
-
In the section Exception match:
-
In the Source field:
-
Select the checkbox.
-
On the right side, click [...].
-
Select the required object.
Note - If you do not see the host object listed, you may need to create it in SmartEvent (see System Administration).
-
Click OK.
-
-
In the Destination field:
-
Select the checkbox.
-
On the right side, click [...].
-
Select the required object.
Note - If you do not see the host object listed, you may need to create it in SmartEvent (see System Administration).
-
Click OK.
-
-
In the Connection occurred at least field, enter the relevant number of times.
-
In the times over a period of field, enter the relevant number of seconds.
-
-
In the section Severity and Reactions:
-
In the Severity field, select the required level.
-
In the Reactions section, select the application option:
-
Default.
-
Specific > click [...] > select or add the relevant Automatic Reactions > click OK (see Automatic Reactions).
-
-
Optional: In the Comment field, enter a significant text.
-
-
Click OK.
-
Click Menu > File > Save.
-
Click Menu > Actions > Install Event Policy.