Alerting

CheckPoint Firewall Block APP

dteixeira98
Engager

Hi everyone,

so I´m using CheckPoint Firewall Block app to block some ip's. 
If I try to block them manually like this:

dteixeira98_0-1631872888694.png

I'm getting this:

dteixeira98_1-1631872967103.png

The IP is being blocked.

However, when I'm configuring an alert condition to block it automatically :

dteixeira98_2-1631873145460.png

I get this:

dteixeira98_5-1631873289142.png

so, the IP is not being blocked.

 

Someone had the same problem and know how to solve it?

Labels (2)
0 Karma
Get Updates on the Splunk Community!

Detecting Brute Force Account Takeover Fraud with Splunk

This article is the second in a three-part series exploring advanced fraud detection techniques using Splunk. ...

Buttercup Games: Further Dashboarding Techniques (Part 9)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Buttercup Games: Further Dashboarding Techniques (Part 8)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...