> Source: [sk181190](https://support.checkpoint.com/results/sk/sk181190)

# sk181190 - How to configure email notifications for Expert Mode login using SmartEvent Automatic Reactions

| Property | Value |
|----------|-------|
| Solution ID | sk181190 |
| Date Created | 2023-07-18 |
| Last Modified | 2026-05-05 |
| Technical Level | General |
| Products | Security Management Server |
| Versions | R82.10, R82, R81.20, R81.10 (EOS) |
| OS | Gaia |

## Solution

### Overview

We recommend that to enhance security, you implement an alert notification system for Expert mode login events. This measure will help to quickly detect and respond to potential security breaches.

#### Options to configure the alert notifications:

|--------|------------------------------------------------------------------------------------------|--------------------------------------------------------------------|
| Option | Brief Description                                                                        | Instructions                                                       |
| 1      | Connect the Security Management Server / Domain Management Server to the Infinity Portal | See [sk181230](https://support.checkpoint.com/results/sk/sk181230) |
| 2      | Use the SmartEvent Automatic Reaction                                                    | Below in this article                                              |

This article provides a step-by-step guide for setting up email alerts using **SmartEvent Automatic Reaction**. The alerts are triggered when Expert mode audit logs are detected to ensure timely notifications for critical events. For a comprehensive range of notifications, including SMS and team alerts, we recommend the Option #1 (connecting the Management Server to the Infinity Portal).

### Prerequisites for SmartEvent Automatic Reaction

1. The required software version is installed on Gaia Servers:

   |----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
   | Gaia Servers                                                                                                                                                                                                                                                                           | Supported Versions                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
   | * Security Gateways that run the Gaia OS (including ElasticXL, Maestro, Scalable Chassis, VSX, VSNext) * Security Management Servers * Multi-Domain Security Management Servers * Multi-Domain Log Servers * Dedicated Log Servers * Dedicated SmartEvent Servers * Standalone Servers | * R82 and higher (PMTR-93037) * [R81.20 Jumbo Hotfix Accumulator](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20/Default.htm) - Take 24 and higher (PRJ-47513) * [R81.10 Jumbo Hotfix Accumulator](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.10/Default.htm) - Take 110 and higher (PRJ-47512) * [R81 Jumbo Hotfix Accumulator](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81/Default.htm) - Take 87 and higher (PRJ-47511) * [R80.40 Jumbo Hotfix Accumulator](https://sc1.checkpoint.com/documents/Jumbo_HFA/R80.40/Default.htm) - Take 198 and higher (PRJ-47510) |
   | * Spark Firewall Appliances that run the Gaia Embedded OS                                                                                                                                                                                                                              | * *Planned*                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |

2. The SmartEvent Software Blade is enabled on a Security Management Server / dedicated SmartEvent Server.

   * For more information about the SmartEvent Software Blade, see [sk93970](https://support.checkpoint.com/results/sk/sk93970).

   * For more information about SmartEvent deployments, see the [Logging and Monitoring Administration Guide](https://support.checkpoint.com/product/451) for your version (select the "Documentation" resource) \> search for the "Deploying SmartEvent" section.

3. An SMTP server in the organization for configuring email alerts.

### Configuring alert notification with SmartEvent Automatic Reaction

#### Part 1 - Open the SmartEvent GUI client

1. In SmartConsole, on the left navigation panel, click the **Logs \& Monitor** view.

2. At the top, click **\[+\]** to open a new tab.

3. At the bottom, in the **External Apps** section, click **SmartEvent Settings \& Policy**.

#### Part 2 - Configure the Event Policy and Name

1. Go to **Event Policy** \> **User Defined Events** \> and right-click **New**.

2. In the **Event Definition Wizard** , select "**that is based on an existing event**".

3. Select **Event Policy** \> **Informational** \> **Policy Installation** \> **Next**.

4. Specify an **Event Name** and description. Change the **Severity** to **High** \> **Next**.

5. Select "**a single log. Use this setting when defining an event where a single log is sufficient to generate an event...** " (default) \> **Next**.

#### Part 3 - Configure the Event Product

1. Click **Deselect All** to clear all selected products.

2. Click **Add Product** \> in the **Product Name** field, enter **Expert Shell** \> click **OK**.

   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk181190/product_expert_shell202308021113481.png)
3. Select the checkbox **Expert Shell** (do **not** select any other checkboxes) \> click **Next**.

4. Select **Edit all products filters** \> **Next**.

#### Part 4 - Configure the fields for the event filter

1. Click **Show More Fields** \> **New Field** and enter:

   |------------------------|-----------------------------------|-------------------------------------------------------------------|
   | Field                  | What to Enter                     | Comment                                                           |
   | **Name**               | *subject*                         | The letter 's' must be in the lower case                          |
   | **Displayed Name**     | *subject*                         | The letter 's' must be in the lower case                          |
   | **Description**        | Your desired subject of the event |                                                                   |
   | **Related Product(s)** | *Expert Shell*                    | The same string you entered in Part 3 in the "Product Name" field |

   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk181190/subject_1202307022156212.png)
2. Click **OK**.

3. Select the field **subject** (with the letter 's' in the lower case) \> click **Add** \> in the **Value** field, enter the asterisk character "**\*** " \> click **OK**:

   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk181190/subject_2202307022157474.png)
4. Click **OK**.

   The filter should look like this Event example:

   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk181190/subject_3202307022158075.png)
5. Click **Next**.

6. Click **Finish**.

#### Part 5 - Configure the Automatic Reaction

1. After the new event is loaded, select "**NOT**" to install the Event Policy now.

   The new event now appears in the **User Defined Events** section.
2. Hover the mouse cursor over the new event \> examine the **Automatic Reaction** field.

   If you already have an Automatic Reaction of an email configured, then select it. Otherwise, configure a new one.
3. Click **'...'** \> **Add new** \> **Mail** \> configure the required email settings.

4. Click **OK** and select the new alert.

5. Select "**Send automatic reactions but don't generate an event**".

6. The event should look similar to this example:

   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk181190/export_shell_event202308021215011.png)
7. When the event is ready to use, click **Install Event Policy**.

Now, when a user logs in to the Expert mode, the log in event is triggered. A new audit log appears in the **Audit** logs view and an email alert is sent.

Example:

![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk181190/final-mail-alert202308021218422.png)

<br />

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
