Event Forwarding - Push to SIEM

Infinity Portal can forward logs to SIEM in three formats: Syslog, LEEF, or CEF.

Prerequisites:

  • The SIEM server must support TLS 1.2.

  • The OpenSSL CLI must be installed on your computer.

  • Make sure your network and SIEM server allow inbound connections using Fully Qualified Domain Names (FQDNs) listed below:

    File

    FQDN

    Europe (EU)

    whitelist-cidr.eu.datatube.checkpoint.com/

    United States (US)

    whitelist-cidr.us.datatube.checkpoint.com/

    Asia-Pacific (AP, Australia)

    whitelist-cidr.ap.datatube.checkpoint.com/

    United Arab Emirates (AE)

    whitelist-cidr.ae.datatube.checkpoint.com/

    Important - The FQDN configuration is mandatory for new users. If you previously configured a static IP address, we recommend replacing it with the FQDN address shown in the table above.

File Extensions

File 

Description

<CA>.key

Private key

<CA>.pem

Public key

.csr

Certificate Sign Request

.crt

File you create when you sign the .csr file with the <CA>.key file and the <CA>.pem file.

.pfx

If you use an existing domain certificate, this file contains the [CA].key file and <CA>.pem file.

After configuring the destination, add a forwarding rule with this destination. For more information, see Managing Forwarding Rules.