Audits

On the Audits page, you can monitor the actions of each user in the portal.

Viewing Audit Events

To view audit events:

  1. In the Check Point Portal, go to > Audits.

    The Audits window opens.

  2. To update the displayed audit events, click Refresh:

    • Severity - Severity of the action. Possisble values: Notice, Info, Warning, Critical

    • User - User who performed the action

    • Time - Date and time when the audit event was created, in DD/MM/YY, HH:MM:SS format

    • Service - Portal service in which the action was performed.

    • Category - The feature area of the portal where the audited action occurred.

    • Type - The specific event type recorded in the audit log, such as Login, Auto Sync, or App Trial.

To filter audit events:

  1. Click the Filter icon .

    The Filters pane shows on the right side of the table.

  2. Apply one or more filter criteria to find a specific audit:

    • Auth Type

    • Category

    • Created By

    • From Date - Select the start date

    • Service

    • Severity

    • To Date - Select the end date

  3. To clear filter data, click Clear all.

Note - Audit logs are kept on record for a minimum of one year.

Audit Event Schema

Audit events are exported in Syslog format. Each record contains a set of fields that identify the account, event type, severity, and additional event attributes. You can use these fields to parse audit records, ingest them into SIEM platforms, and create correlation and detection rules.

Example Audit Event

Copy
{
"id": "12345678-1234-1234-1234-123456789abc"
"tenantId": "xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx"
"severity": "Notice"
"category": "Authentication"
"event":"Change Account"
"module":"Portal"
"eventData":"Changed account successfully from Demo"
"createdBy":"aaa@checkpoint.com"
"createdAt":"2026-09-03T12:17:04.069Z"
"visibility":"customer"
}

Event Field Definitions

Field

Description

id

Unique identifier of the audit event

tenantId

Unique identifier of the account in which the event occurred

severity

Severity level assigned to the audit event, for example, Info, Warning, Critical

category

Category associated with the audit event, for example, Authentication or Access Control

event

Name of the audited action

module

Product module that generated the audit event, for example, Portal or Mobile Security

eventData

Additional information about the audited action.

createdBy

User account that initiated the action.

createdAt

Date and time when the audit event was created, in UTC.

visibility

Visibility scope assigned of the audit event.