Push to SIEM

Check Point Portal can forward logs to SIEM in three formats: Syslog, LEEF, or CEF.

Supported Check Point Portal Services

Event Forwarding can send data from these Check Point Portal services:

  • Browse Security

  • Connect

  • Email Security

  • Endpoint Security

  • Mobile Security

  • Management & Smart-1 Cloud

  • Check Point SASE

  • Spark Management

  • WAF Application Security - Application Security

  • Workforce AI Security

Prerequisites

  • The SIEM server must support TLS 1.2.

  • The OpenSSL CLI must be installed on your computer.

Network Access Requirements

To receive events from Check Point Portal, the SIEM must accept inbound connections on a dedicated listener port.

Configure your network and firewall policy to allow inbound traffic from Check Point Portal regional endpoints, using FQDN-based filtering.

Use the regional Fully Qualified Domain Name (FQDN) that corresponds to your Check Point Portal location:

Region

FQDN

Ports

Europe (EU)

whitelist-cidr.eu.datatube.checkpoint.com/

514, 6514

United States (US)

whitelist-cidr.us.datatube.checkpoint.com/

514, 6514

Asia-Pacific (AP, Australia)

whitelist-cidr.ap.datatube.checkpoint.com/

514, 6514

India (IN)

whitelist-cidr.in.datatube.checkpoint.com/

514, 6514

United Arab Emirates (AE)

whitelist-cidr.ae.datatube.checkpoint.com/

514, 6514

Important - FQDN-based filtering is required for new deployments and recommended for existing deployments to prevent connectivity issues when backend infrastructure changes. Do not replace the FQDN endpoints with fixed network addresses.

Note - During onboarding, new customers can use only ports 514 and 6514.

File Extensions

File 

Description

<CA>.key

Private key

<CA>.pem

Public key

.csr

Certificate Sign Request

.crt

File you create when you sign the .csr file with the <CA>.key file and the <CA>.pem file.

.pfx

If you use an existing domain certificate, this file contains the [CA].key file and <CA>.pem file.

After configuring the destination, add a forwarding rule with this destination. For more information, see Managing Forwarding Rules.