On each machine that sends Windows Events, configure the Windows Audit Policy.
To configure the windows audit:
C:\Program Files\CheckPoint\WinEventToCPLog\R65\bin.On 64 bit computers, the path starts with C:\Program files (x86).
windowEventToCPLog -l <ipaddr>, where <ipaddr> is the IP address of the Log Server that receives the Windows Events.
windowEventToCPLog -a <ipaddr>, where <ipaddr> is the IP address of each machine that sends Windows Events.
windowEventToCPLog -s, where you are prompted for an administrator name and the administrator password that to be registered with the windowEventToCPLog service.
The administrator that runs the windowEventToCPLog service must have permissions to access and read logs from the IP addressed defined in this procedure. This is the IP address of the computer that sends Windows events.