Skyline Configuration on Check Point Servers that run Gaia OS - Other Monitoring Tools

Best Practice - Use the Prometheus Server with the Grafana Server.

See Skyline Configuration on Check Point Servers that run Gaia OS - Prometheus with Grafana.

Note:

By default, Skyline on a Check Point Server uses a proxy server configured in one of these:

  • SmartConsole > Global properties > Proxy.

  • SmartConsole > the object of the Check Point Server > Network Management > Proxy.

  • The proxy server configured in the Gaia operating system on this Check Point Server.

If this Check Point Server must connect to a specific destination directly (to bypass the configured proxy server), then configure an exception:

  1. Connect to the command line on this Check Point Server.

  2. Log in to the Expert mode.

  3. Edit this file:

    vi /opt/CPotelcol/no_proxy

    Skyline uses this file to configure the standard environment variable named "NO_PROXY".

  4. Add a comma-separated list of domains, IP addresses, or networks to exclude from the configured proxy server.

    Example:

    localhost,my.collector.host

  5. Save the changes in the file and exit the editor.

Skyline supports these third-party monitoring tools (to configure these tools, refer to the third-party official documentation):

This section applies to these Check Point Servers:

  • Security Gateways / VSX Gateways.

  • ClusterXL Members.

    In a Cluster, you must configure all the Cluster Members in the same way.

  • Security Groups on Scalable Platforms (ElasticXL Cluster, Maestro, and Scalable Chassis).

  • Security Management Servers.

  • Multi-Domain Security Management Servers.

  • Multi-Domain Log Servers.

  • Log Servers.

  • SmartEvent Servers.

  • Endpoint Security Management Servers.

  • Endpoint Policy Servers.

Step 1 - Install the Third-Party Monitoring Tool

Refer to the third-party official documentation.

Step 2 - Install the OpenTelemetry Agent and OpenTelemetry Collector on the Check Point Server

Step 3 - Configure the OpenTelemetry Collector on the Check Point Server to work with the Third-Party Monitoring Tool

Step 4 - Configure the filter for the OpenTelemetry Collector exported metrics

Step 5 - Configure Access Control Policy

If you configured Skyline on a Security Gateway, ClusterXL, or Scalable Platform Security Group, then you must make sure your Access Control Policy allows the connection to the Third-Party Monitoring Tool to send the exported metrics.

You must configure the required rule on the Management Server (in SmartConsole or with Management API) and install the policy.

See the: