> Source: [sk184915](https://support.checkpoint.com/results/sk/sk184915)

# sk184915 - Missing Protection Details fields for External IOC Feed logs

| Property | Value |
|----------|-------|
| Solution ID | sk184915 |
| Date Created | 2026-06-15 |
| Last Modified | 2026-06-16 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82, R81.20 |

## Symptoms

- * After upgrading to R81.20 or R82, some logs generated by External IoC Feed protections do not display **Protection Name** , **Indicator Name** , and **Observable Name** fields in the log's **Protection Details** section.

  |-----------------------------------------------------------------------------------------------|-----------------------------------------------------------------------------------------------|
  | Example -- Protection Details in R81.10                                                       | Example -- Protection Details in R81.20 and R82                                               |
  | ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk184915/ioc_log_old-1202605071102321.jpg) | ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk184915/ioc_log_new-1202605071102582.jpg) |

  <br />

* The issue occurs only when the matched observable is defined as a subnet (for example, `19.0.0.0/24`), or an IP range (for example, `19.1.0.1--19.1.0.10`). When the observable is defined as a single IP address (for example, `19.2.0.1`), all fields are populated correctly in the log.

## Cause

The observable mapping database is not properly updated for observables defined as subnets or IP ranges, which results in missing fields in the `Protection Details` section.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
