Viewing Search Results

Query results can include tens of thousands of log records. To prevent performance degradation, SmartConsoleClosed Check Point GUI application used to manage a Check Point environment - configure Security Policies, configure devices, monitor products and events, install updates, and so on. only shows the first set of results in the Results pane. Typically, this is a set of 50 results.

Scroll down to show more results. As you scroll down, SmartConsole extracts more records from the log index on the Security Management ServerClosed Dedicated Check Point server that runs Check Point software to manage the objects and policies in a Check Point environment within a single management Domain. Synonym: Single-Domain Security Management Server. or Log ServerClosed Dedicated Check Point server that runs Check Point software to store and process logs., and adds them to the results set. See the number of results above the Results pane.

For example, on the first run of a query, you can see the first 50 results out of over 150,000 results. When you scroll down, you can see the first 100 results out of over 150,000.

The Tops pane, on the right side of the Results pane, shows the top statistics such as Top Sources, Top Actions, and so on. Starting from Jumbo Hotfix AccumulatorClosed Collection of hotfixes combined into a single package. Acronyms: JHA, JHF, JHFA. Take 36, there are also statistics for Top Access Rules and Top Log Types.

Notes:

  • Top statistics are estimated according to the partial log results already shown on the screen. They are not calculated for the entire query timeframe.

  • A query that refers to these log fields is not resolved:

    • Scan result

    • Destination DNS Hostname

Customizing the Results Pane

By default, SmartConsole shows a predefined set of columns and information based on the selected blade in your query. This is known as the Column Profile. For example:

  • The DLP column profile includes columns for: Blade, Type, DLP Incident UID, and severity.

  • The Threat Prevention column profile includes columns for: Origin, Action, Severity, and Source User.

A column profile is assigned based on the blade that occurs most frequently in the query results. This is called Automatic Profile Selection, and is enabled by default.

The Column Profile defines which columns show in the Results Pane and in which sequence. You can change the Column Profile as necessary for your environment.

To use the default Column Profile assignments:

  • Right-click a column heading and select Columns Profile > Automatic Profile Selection.

To manually assign Column Profile assignments by default:

  • Right-click a column heading and select Columns Profile > Manual Profile Selection.

To manually assign a different Column Profile:

  1. Right-click a column heading and select Columns Profile.

  2. Select a Column Profile from the options menu.

To change a Column Profile:

  1. Right-click a column heading and select Columns Profile > Edit Profile.

  2. In the Show Fields window, select a Column Profile to change.

  3. Select fields to add from the Available Fields column.

  4. Click Add.

  5. Select fields to remove from the Selected Fields column.

  6. Click Remove.

  7. Select a field in the Selected Fields.

  8. Click Move Up or Move Down to change its position in the Results Pane.

  9. Double-click the Width column to change the default column width for the selected field.

To change the column width:

  1. Drag the right column border in the Results Pane.

  2. Right-click and select Save Profile.

    Changes made to the column are saved for future sessions.

Creating Custom Queries

Queries can include one or more criteria. You can modify an existing predefined query or create a new one in the query box.

To modify a predefined query:

Click inside the query box to add search filters.

To save the new query in the Favorites list:

  1. Click Queries > Add to Favorites.

    The Add to Favorites window opens.

  2. Enter a name for the query.

  3. Select or create a new folder to store the query

  4. Click Add.

Selecting Query Fields

You can enter query criteria directly from the Query search bar.

To select field criteria:

  1. If you start a new query, click Clear to remove query definitions.

  2. Put the cursor in the Query search bar.

  3. Select a criterion from the drop-down list or enter the criteria in the Query search bar.

Selecting Criteria from Grid Columns

You can use the column headings in the Grid view to select query criteria. This option is not available in the Table view.

To select query criteria from grid columns:

  1. In the Results pane, right-click on a column heading.

  2. Select Add Filter.

  3. Select or enter the filter criteria.
    The criteria show in the Query search bar and the query runs automatically.

Manually Entering Query Criteria

You can enter query criteria directly in the Query search bar. You can manually create a new query or make changes to an existing query that shows in the Query search bar.

As you enter text, the Search shows recently used query criteria or full queries. To use these search suggestions, select them from the drop-down list.