Jump to main content
Email Security Administration Guide
Index
Email Security Administration Guide
Check Point Support
  1. Home
  2. Managing Security Events
  3. Reviewing Security Events
  4. Retention of Security Events
  • Important Information
  • Introduction to Email Security
  • Getting Started
  • Configuring Security Engines
  • Email Protection
  • Messaging Apps Protection
  • File Storage Protection
  • Compromised Account (Anomaly) Detection
  • Partner Risk Assessment (Compromised Partners)
  • Cloud SMTP Relay
  • Managing Security Exceptions
  • Managing Security Events
    • Dashboards, Reports and Charts
    • Reviewing Security Events
      • Events
      • Reviewing Phishing Events
      • Reviewing Malware Events
      • Automatic Ingestion of End User Reports
      • Retention of Security Events
    • Searching for Emails
    • Remediating Compromised Accounts
    • System Settings
    • SIEM / SOAR Integration
    • CrowdStrike Integration
  • Managing Quarantine
  • Customization
  • SmartConfig Recommendations
  • Incident Response as a Service (IRaaS)
  • DMARC Management
  • Security Posture Management (SSPM)
  • Leaked Credentials
  • Security Awareness Training
  • Video Tutorials
  • Appendix

Retention of Security Events

Email Security retains security events and shows them in the Events dashboard for 12 months.

To export events to external sources and retain them, see:

  • Forwarding Logs in Syslog Format

  • Exporting security events via APIs

Generated by <oXygen/> XML WebHelp
07 August 2026
© 2022 - 2026 Check Point Software Technologies Ltd.