System Administration

To maintain your SmartEvent system, you can do these tasks from the General Settings section of the Policy tab:

Adding a Host or Network Object to SmartEvent

Network Objects are the objects that are synchronized from the Management ServerClosed Check Point Single-Domain Security Management Server or a Multi-Domain Security Management Server. database as well as user-defined additional objects. These objects from the Management Server are added to SmartEvent during the initial sync and updated at set intervals.

Best Practice - Add new Host and Network objects in SmartConsoleClosed Check Point GUI application used to manage a Check Point environment - configure Security Policies, configure devices, monitor products and events, install updates, and so on. and not in SmartEvent GUI.

  1. In SmartConsole, from the left navigation panel, click the Logs & Monitor view.

  2. At the top, click + to open a new tab.

  3. In the bottom section External Apps, click SmartEvent Settings & Policy.

  4. Click the folder General Settings > Objects > the object Network Objects.

  5. Click Add > Host or Network.

  6. Configure the object:

    • For a Host object:

    • For a Network object:

      • In the Name field, enter a significant name.

      • In the Network Address field, enter the required network IP address.

      • In the Net Mask field, enter the required network mask.

      • Optional: In the Comment field, enter a significant text.

  7. Click OK.

  8. Click Menu > File > Save.

  9. Click Menu > Actions > Install Event Policy.

Defining the Internal Network

Note - Some network objects are copied from the Management server to the SmartEvent Server during the the initial sync and updated afterwards. You cannot configure the internal network until the initial sync is complete.

To help SmartEvent conclude if events originated internally or externally, you must define the Internal Network.

The Internal Network defines hosts, networks, or groups that are part of the network behind the organization's perimeter.

These are the options to calculate the traffic direction:

  • Incoming - All the sources are external to the network and all destinations are internal.

  • Outgoing - All sources are in the network and all destinations are external.

  • Internal - Sources and destinations are all in the network.

  • Other - A mixture of internal and external values makes the result indeterminate.

To define the Internal Network:

  1. In SmartConsole, from the left navigation panel, click the Logs & Monitor view.

  2. At the top, click + to open a new tab.

  3. In the bottom section External Apps, click SmartEvent Settings & Policy.

  4. Click the folder General Settings > Initial Settings > the object Internal Network.

  5. In the left panel Not in Internal Network, select one or more relevant objects (press and hold the CTRL key).

    We recommend you add all internal Network objects, and not Host objects.

  6. Click Add.

  7. In the right panel In Internal Network, you can click Add New to add a new Host or Network object.

    See Adding a Host or Network Object to SmartEvent.

  8. Click Menu > File > Save.

  9. Click Menu > Actions > Install Event Policy.