Forensics Data
Endpoint Security collects forensics data from endpoints that you can export to a data analytics tool for analysis and create policies accordingly to prevent attacks. For more information on forensics, see Automated Attack analysis.
You can perform following actions with the forensics data:
-
Exporting to Check Point's Threat Hunting.
-
Sending Forensics Data to Third-Party Analytics Tool
-
Downloading Forensics Reports
Endpoint Security exports the forensic data only in the JSON format. Make sure that the third-party data analytics tool accepts the data in the JSON format.
Sending Forensics Data to Third-Party Analytics Tool
You can send the forensics data to a third-party data analytics tool, such as Elastic that accepts the data in the JSON format.
-
Navigate to Threat Prevention > Manage > Manage Data Tube.
-
In the URL field. enter the URL of the third-party data analytics tool.
Note:Endpoint Security does not support to enter user credentials for the third-party analytics tool for authentication.
-
Click Save.
The system applies the policy to all endpoints.
Endpoints send the forensic data in JSON format to the third-party data analytics tool.