How can I check what IP generated this alert (Full Version)

All Forums >> [Threat Management Gateway (TMG) 2010] >> General



Message


ice.rapoarte -> How can I check what IP generated this alert (4.Dec.2013 7:10:32 AM)

I received this alert

The Malware Inspection Filter detected malware and either removed it or blocked the message. See the Web Proxy log for details.

How can I see what IP was involved.

Tnx in advance for your support




elmajdal -> RE: How can I check what IP generated this alert (4.Dec.2013 11:00:59 AM)

quote:

ORIGINAL: ice.rapoarte

See the Web Proxy log for details.




Go to the Logging & Reports node in the TMG firewall console and click the Logging tab. set the Log Time and configure the Malware Inspection field for Blocked.




ice.rapoarte -> RE: How can I check what IP generated this alert (4.Dec.2013 11:02:53 AM)

I have searched there, but when I select that filter nothing appears. I used Malware Inspection Action filter.
Loging is enabled.

Ps: I am new with tmg:)




elmajdal -> RE: How can I check what IP generated this alert (4.Dec.2013 11:34:32 AM)

check the timing filter.

if you selected a timing that didnt have any blocked traffic, then nothing will be displayed.




ice.rapoarte -> RE: How can I check what IP generated this alert (4.Dec.2013 11:37:07 AM)

I selected last 24 hours. That alert was generated this morning. Any other advice?




PatrickM -> RE: How can I check what IP generated this alert (6.Dec.2013 1:44:25 AM)

Is logging set to database MSDE (default) or Text LOG file?
This might be relevant since text file logging does not enable you to travel back in the logs using the GUI, if that is the case go directly to the log files specifically.

-PatrickM-




ice.rapoarte -> RE: How can I check what IP generated this alert (6.Dec.2013 1:59:53 AM)

It's set to MSDE.




PatrickM -> RE: How can I check what IP generated this alert (11.Dec.2013 1:11:25 AM)

does the log work for other individual searches?
* All hits..
* IP
* Malware Inspection

running out of ideas...




futcoinsboy -> RE: How can I check what IP generated this alert (9.May2014 8:20:30 AM)

Time and configure the Malware Inspection field for Blocked.

___________________________________

Aion Kinah




Page: [1]