> Source: [sk118875](https://support.checkpoint.com/results/sk/sk118875)

# sk118875 - How to submit a False Positive case for Threat emulation? 

| Property | Value |
|----------|-------|
| Solution ID | sk118875 |
| Date Created | 2017-07-12 |
| Last Modified | 2021-12-28 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R81.10 (EOS), R81 (EOS) |
| OS | Gaia |

## Solution

In order to submit False Positive report for Threat Emulation, collect the following information and [open a support ticket with Check Point Support:](https://www.checkpoint.com/support-services/contact-support/)  
1- Full information on the deployment used for emulation - local emulation / cloud / or dedicated TE appliance.  

2- Output of next commands:  

`# tecli ad sc all `  
`# tecli s d all `  
`# tecli ad en ver `  
`# cpstat threat-emulation -f contract`  

**NOTE:** *In case the deployment includes Security Gateway and TE appliance please collect this information from both.*   

3-Original file suspected as a false positive. \[*Archive the file with password = infected* \]  

4-Double click the log in SmartLog to open it.   

* Click the copy icon on the upper-right side to copy the log text.

* Click the Summary button to download the Summary report.

<br />

5-Please provide the ThreatEmulation_dataXML file from Report file. \[*This file will have no extention*\]

The XMLData is created once the TE report from the SmartConsole is opened in the browser, and can be found in the following directory: C:\\Users\\user_name\\AppData\\Local\\Temp\\IncidentAttachments\\TEReports\\{report_id}\\data\\ /ThreatEmulation_dataXML

<br />

Please go to the SmartView Tracker/SmartLog, for Management server R77.X, or to SmartLog, for Management server R80.X, and open the log of the suspected file.

<br />

<br />

Click to View Report \[not download\].

<br />

<br />

An IE browser will open the report and you will find the report_ID in the URL.

<br />

<br />

**Example:**

C:\\Users\\user_name\\AppData\\Local\\Temp\\IncidentAttachments\\TEReports\\{report_id}\\data\\ /ThreatEmulation_dataXML

<br />

[5- CPinfo](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk92739) output files from all relevant machines \[*Security Gateway, Security Management server,TE appliance* \].   

<br />

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
