AWS Security Hub

You can configure your Check Point Security Management Servers to send Threat Prevention events to the AWSClosed Amazon® Web Services. Public cloud platform that offers global compute, storage, database, application and other cloud services. Security Hub.

The AWS Security Hub service gives you a comprehensive view of your security alerts and security posture across your AWS accounts.

For more information, see the AWS Security Hub documentation.

Prerequisites

Note - To use the AWS Security Hub APIs, the Security Management Server must have outbound internet connectivity.

Subscribing to the Check Point CloudGuard Network in AWS Security Hub

Configuring the Check Point Security Management Server to Send Events to the AWS Security Hub

Use these steps to configure the Check Point Security Management Server to send findings to your AWS Security Hub account.

Enabling Security Hub on the Security Management Server

You can activate the Security Hub feature only after the configuration is complete.

After the Security Hub is configured and enabled on the Security Management Server, it is possible to make sure that the status shows "Security Hub Service is currently enabled and sending logs to AWS". See Displaying the Security Hub Integration Status.

Disabling Security Hub on the Security Management Server

If you disable the feature, it stops the Security Management Server from sending logs to AWS Security Hub service.

Displaying the Security Hub Integration Status

You can see the status of Security Hub integration on the Security Management Server.

Configuring Debug Mode

When Debug mode is activated, detailed logs of the Security Hub internal state are generated and saved to a file.

Note - The Debug mode is disabled by default.

Additional Information about CloudGuard Network in Security Hub

Only logs from these Software Blades and features are sent to AWS Security Hub:

For more information about Finding, select the Finding ID and see ProductFields.

Notes:

  • GeneratorId represents the Security Management Server's host name.

  • CreatedAt time is concurrent to the host time.

  • To filter in AWS, use: Product name is "CloudGuard Network" to see all Check Point CloudGuard Network findings.

  • For Security Management Server High Availability:

    • The configuration is synched between the Active and Standby servers.

    • After failover, enable the Security Hub feature in the Active Security Management Server.

Accessing Security Hub Logs for Troubleshooting

These are the log files on the Management Server:

/var/log/CPcme/cme_log_reporter.log*

Log Exporter

As part of the configuration to send security events, the Log Exporter feature is used.

A new Log Exporter instance is added and monitored by the cpwd with the name: EXPORTER.CME_LOG_REPORTER

For more information about the Log Exporter, see sk122323.

Limitations