0 Replies Latest reply on Sep 2, 2013 9:43 PM by lichnt

    Get information at packet as custome type of SIEM

    lichnt

      Hi all,

      I collect log of FW checkpoint ,

      i have problem as:

      i delete object (host object)  when at checkpoint has log:

      01.png

      but with log of checkpoint when delete any object : host, user, network... as delete object. I see at packet has:

       

      02.png

      ObjectType and ObjectTable are two variables i think has know i delete detail for object. It help get information for forensic . I define as custome type but when i use it at  rule policy for correlation engine but it not run .when i recieve new log , custome type i define it have not Advanced Details.

      Can you help me?