Configuring Logging
Each Endpoint Security client sends logs to the Endpoint Security Server (Endpoint Policy Server Endpoint Policy Server improves performance in large environments by managing most communication with the Endpoint Security clients. Managing the Endpoint Security client communication decreases the load on the Endpoint Security Management Server, and reduces the bandwidth required between sites. The Endpoint Policy Server handles heartbeat and synchronization requests, Policy downloads, Anti-Malware updates, and Endpoint Security client logs. or Endpoint Security Management Server
A Security Management Server that manages your Endpoint Security environment. Includes the Endpoint Security policy management and databases. It communicates with endpoint clients to update their components, policies, and protection data.) to which the client is connected.
To see all collected logs together in the Logs tab of the SmartConsole Check Point GUI application used to manage a Check Point environment - configure Security Policies, configure devices, monitor products and events, install updates, and so on. Logs & Monitor view, you must configure Log Indexing for each Endpoint Security Server in the SmartConsole.
Do this procedure for each Endpoint Security Server.
To configure Logging from one Endpoint Security Server to a different Endpoint Security Server:
-
Open SmartConsole and connect to the Endpoint Security Management Server
Dedicated Check Point server that runs Check Point software to manage the objects and policies in a Check Point environment within a single management Domain. Synonym: Single-Domain Security Management Server..
-
Open the Endpoint Security Management Server
Check Point Single-Domain Security Management Server or a Multi-Domain Security Management Server. object.
-
In the tree of the window that opens, select Logs > Log Server.
-
Select Enable Log Indexing.
-
Click OK.
-
Select Menu > Install Database and install the database on all hosts.
-
Run
cprestart
on the Endpoint Security Management Server.