> Source: [sk110157](https://support.checkpoint.com/results/sk/sk110157)

# sk110157 - SAM rules are occasionally not deleted in SmartView Monitor

| Property | Value |
|----------|-------|
| Solution ID | sk110157 |
| Date Created | 2016-02-25 |
| Last Modified | 2018-11-27 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |

## Symptoms

- * SAM rules are occasionally not deleted in SmartView Monitor:

  1. In SmartView Monitor, go to *Tools* menu - click on *Suspicious Activity Rules...*
  2. Add the desired rules
  3. Select the SAM rule you wish to delete - click on *Remove* button
  4. This SAM rule still appears in this *Enforced Suspicious Activity Rules* window
* SmartView Tracker log shows that the selected SAM rule was cancelled (i.e., deleted):  

  `sys_message: Cancelled the following dynamic (SAM) rule: ...`

* Output of the *fw sam -v -M -j all* command on the Security Gateway still shows the selected SAM rule.

* Deleting *all* SAM rules at once works correctly:  
  * In SmartView Monitor - *Tools* menu - click on *Suspicious Activity Rules...* - click on *Remove All* button
  * On Security Gateway, run the *fw sam -v -D* command

## Cause

Duplicate SAM rules exist in the SAM database on the Security Gateway. Therefore, clicking on the "*Remove*" button removes only one rule instance.

**Note** : By the current design, since the *Enforced Suspicious Activity Rules* window provides a display of the currently enforced rules, if the system administrator adds a rule that is shadowed by another rule, the shadowed rule remains hidden. For example, if a rule was defined for dropping all HTTP traffic and an additional rule is defined for rejecting HTTP traffic, then only the drop rule, which is the dominant rule, will be displayed.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
