> Source: [sk104378](https://support.checkpoint.com/results/sk/sk104378)

# sk104378 - How to submit a False Positive case for Anti-Bot and Anti-Virus protections

| Property | Value |
|----------|-------|
| Solution ID | sk104378 |
| Date Created | 2015-01-22 |
| Last Modified | 2025-01-16 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20, R81.10 (EOS), R81 (EOS) |

## Solution

To submit a False Positive report for Anti-Bot and Anti-Virus, collect the required information and [open a support ticket with Check Point Support](https://www.checkpoint.com/support-services/contact-support/):

1. Screenshots and complete text of the suspected false positive logs from the SmartConsole (Logs view) / SmartView web portal (Logs view):

   1. In the top query field, enter this query and press the Enter key:

      `blade:Anti-Bot or blade:Anti-Virus`

      (For more details, click the link "Query Syntax")
   2. Double-click each relevant log

   3. If you view logs in SmartConsole, then in the top right corner of the log, click the icon "Copy log to clipboard".

      Paste the copied information into a text file (use any text editor).
   4. If you view logs in SmartView web portal, then make sure to expand all section of the log and take a screenshot of the log.

2. Traffic capture (TCPdump / FW Monitor) from involved Security Gateway during the false positive incident.

3. Sample of the relevant file that was prevented or detected, with its MD5 hash for integrity verification.

4. [CPinfo file](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk92739) from the Security Management Server involved in the case.

5. [CPinfo file](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk92739) from the Security Gateway / each Cluster Member involved in the case.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
