> Source: [sk101236](https://support.checkpoint.com/results/sk/sk101236)

# sk101236 - Searching for Incident ID when using UserCheck

| Property | Value |
|----------|-------|
| Solution ID | sk101236 |
| Date Created | 2014-07-23 |
| Last Modified | 2018-01-23 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |
| OS | Gaia |

## Solution

There is a functionality in UserCheck to include a unique "Incident ID" with each block page. This ID is appended to the end of the UserCheck cookie generated for each session.

Network administrators can search for the Incident ID from SmartView Tracker:

1. Click the predefined Application Control/URL Filtering Query -\> More -\> UserCheck Query.
2. In the columns, filter on the "ID" column.
3. Change the search field to "Contains".
4. Enter the Incident ID string in the Text section.

This will allow administrators to pull up the exact log entry for a particular incident ID.  
For more information about the UserCheck portal, refer to [sk83700](http://supportcontent.checkpoint.com/solutions?id=sk83700).

In addition, Network administrators can search for the Incident ID from SmartLog.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
