> Source: [sk164456](https://support.checkpoint.com/results/sk/sk164456)

# sk164456 - Automatic Reaction emails do not include certain fields

| Property | Value |
|----------|-------|
| Solution ID | sk164456 |
| Date Created | 2020-02-03 |
| Last Modified | 2021-08-02 |
| Technical Level | Advanced |
| Products | Security Management Server |
| Versions | R82.10, R82, R81.20, R82.20 |

## Symptoms

- Automatic Reaction emails are sent with missing fields even though they do appear in the GUI logs.

## Cause

General explanation from [sk136672](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk136672):

The Security Gateway generates a log when an event occurs. Over time, the Security Gateway will generate several updates. These updates will not contain all information; rather, they will contain baseline information and changes (the number of bytes sent, the number of attacks, etc.).

Check Point unifies the initial log and updates into one cohesive log that is displayed in the GUI and appears in the debug window in the \<Unified\> section.

This does not apply to the raw log, where the original log is represented as \<Update_0\>, with every consecutive update represented as \<Update_1\>, \<Update_2\>, etc. The updates do not contain the destination field. This is by design, and keeps the updates small. Updates are usually connected by a field called LogUID.

Additional information pertaining to the issue described here:

The emails are sent as Automatic Reactions right after the first \<update\> of the Log.

The \<update\> does not necessarily include all fields which appear in the \<unified\> Log.

This explains why the fields might appear in the GUI but not in the Automatic Reaction emails.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
