Event Forwarding

Event Forwarding is an easy and secure procedure to export Infinity Portal data over the Syslog protocol. You can forward logs, events, and saved application data from your Check Point Infinity Portal account to a SIEM (Security Information and Event Management) provider, such as Splunk, QRadar, or ArcSight. The SIEM providers process large amounts of data and present it for analysis in created dashboards or sent notifications.

Use Case

A typical use case is an organization that uses a number of security vendors, along with Check Point, to protect itself from cyber attacks. And must see all this data from each vendor in a single pane of glass, therefore they have to use an external-analytics platform.

Prerequisites

To forward your data from the Infinity Portal to an external-analytics platform, you must configure these entities:

  • Create a Forwarding Rule - A set of conditions for data forwarding.

  • Set the Destination - Details of your SIEM platform.

  • To secure your server and not expose all IPv4 addresses, you must configure the server to listen to a specific IP address based on region.

    Region

    IP Addresses

    US

    • 52.167.22.194

    • 20.85.1.184

    EU

    • 104.46.50.207

    • 20.73.193.110

    AUS

    • 20.213.113.233

    • 20.92.158.64

    • 20.92.158.102

How to Create a Forwarding Rule

To forward your data to an external-analytics platform, follow these steps.

How to Manage Rules

On the Events page, Forwarding Rules show with the rule name, the services you forward data from, and the name of the destination to which you forward the data.

To add a new Forwarding Rule:

Click the [+] icon or the + Add.

To edit a Forwarding Rule

Put the cursor on the rule and click , then select Edit. Change the rule settings as necessary.

To delete a Forwarding Rule

Put the cursor on the rule and click , then select Delete.

How to Manage Destinations

After you configure your external-analytics platform's destination(s), you can review, edit, search, and delete them in the Manage Destinations window.