> Source: [sk62409](https://support.checkpoint.com/results/sk/sk62409)

# sk62409 - SYN Attack Logs Do Not Display Source or Destination IP Address

| Property | Value |
|----------|-------|
| Solution ID | sk62409 |
| Date Created | 2011-04-14 |
| Last Modified | 2021-10-20 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R81.10 (EOS), R81 (EOS) |

## Symptoms

- SmartView Tracker logs show Protection Name "SYN Attack" in the "General event Information", but do not show any Information in the "Traffic" section of the log. There's no Source, Destination, Service, etc., listed.

## Cause

This behavior is by design.

## Solution

This is the normal, default behavior for the SYN Attack IPS protection.

If all details were always logged in full for every SYN Packet during an attack, there would be signifcant CPU overhead, and it would reduce system performance and throughput, thus the default setting is for less performance overhead.

However, this default can be changed, in the IPS protection settings for SYN Attack. Find the setting here:

IPS -\> Protections -\> By Protocol -\> Network Security -\> TCP -\> SYN Attack -\> (Choose the profile and click edit) -\> Logging Options -\> Track level -\>

Toggle between "Attack Only" and "Individual SYNs", then install policy to make the change take effect for logs that are generated after the policy installation.

Also, the thresholds in the SYN Attack IPS Protection refer to the number of unacknowledged SYNs, not the number of all SYNs.

The threshold number of unacknowledged SYNs is the number of unacknowledged SYNs for all incoming traffic, not the number of unacknowledged SYNs per destination I.P. address.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
