Push to SIEM

Check Point Portal can forward logs to SIEM in three formats: Syslog, LEEF, or CEF.

Supported Check Point Portal Services

Event Forwarding can send data from these Check Point Portal services:

  • Check Point Portal Audit logs

  • Browse Security

  • Connect

  • Email Security

  • Endpoint Security

  • Mobile Security

  • Management & Smart-1 Cloud

  • Check Point SASE

  • Spark Management

  • WAF Application Security - Application Security

  • Workforce AI Security

Prerequisites

  • The SIEM server must support TLS 1.2.

  • The OpenSSL CLI must be installed on your computer.

Network Access Requirements

To receive events from Check Point Portal, the SIEM must accept inbound connections on a dedicated listener port.

Configure your network and firewall policy to allow inbound traffic from Check Point Portal regional endpoints, using FQDN-based filtering.

Use the regional Fully Qualified Domain Name (FQDN) that corresponds to your Check Point Portal location:

Region

FQDN

Ports

Europe (EU)

whitelist-cidr.eu.datatube.checkpoint.com/

514, 6514

United States (US)

whitelist-cidr.us.datatube.checkpoint.com/

514, 6514

Asia-Pacific (AP, Australia)

whitelist-cidr.ap.datatube.checkpoint.com/

514, 6514

India (IN)

whitelist-cidr.in.datatube.checkpoint.com/

514, 6514

United Arab Emirates (AE)

whitelist-cidr.ae.datatube.checkpoint.com/

514, 6514

Important - Customers must configure the FQDN. New customers must use the FQDN, and existing customers must replace any static IP addresses with the FQDN listed above.

Note - During onboarding, new customers can use all ports between 5514-5517 and 7514-7517.

If FQDN-based filtering is not supported

Use IP-based filtering only if your firewall platform does not support FQDN-based rules.

Allow an IP address If FQDN based rules are not supported. Configure your firewall to allow inbound traffic from the IP address returned by a DNS lookup of the required regional domain.

Important - The resolved IP address is not static and may change over time. When using IP-based rules, review and update the configured IP address periodically to maintain connectivity.

Reference IP addresses (IP-based filtering only)

Data Region

Example IP Address

Source Ports

Australia

20.53.179.128/29

514, 6514

Canada

20.116.186.248/29

514, 6514

India

20.207.91.248/29

514, 6514

UAE

20.233.160.96/29

514, 6514

US

20.22.10.32/29

514, 6514

Europe

20.23.152.176/29

514, 6514

Note - These IP addresses are provided for convenience, but they are not guaranteed to remain static. Always prefer FQDN-based rules when possible.

File Extensions

File 

Description

<CA>.key

Private key

<CA>.pem

Public key

.csr

Certificate Sign Request

.crt

File you create when you sign the .csr file with the <CA>.key file and the <CA>.pem file.

.pfx

If you use an existing domain certificate, this file contains the [CA].key file and <CA>.pem file.

After configuring the destination, add a forwarding rule with this destination. For more information, see Managing Forwarding Rules.