In a Multi-Domain Security Management environment, the Security Gateways send logs to the Domain Management Server Check Point Single-Domain Security Management Server or a Multi-Domain Security Management Server. and dedicated Domain Log Servers.
The Multi-Domain Server Dedicated Check Point server that runs Check Point software to host virtual Security Management Servers called Domain Management Servers. Synonym: Multi-Domain Security Management Server. Acronym: MDS. unifies logs, and they can be stored on the Multi-Domain Server or on a dedicated Multi-Domain Log Server
Dedicated Check Point server that runs Check Point software to store and process logs in a Multi-Domain Security Management environment. The Multi-Domain Log Server consists of Domain Log Servers that store and process logs from Security Gateways that are managed by the corresponding Domain Management Servers. Acronym: MDLS..
Starting in R81, Multi-Domain Server supports a dedicated Log Server Dedicated Check Point server that runs Check Point software to store and process logs. (installed on a separate computer) for a Domain.
You can configure a Domain Dedicated Log Server to receive logs only from a specified Domain, and no other Domains can access these logs.
This allows you to locate the dedicated Log Server in a separate network from the Multi-Domain Security Management environment to comply with special regulatory requirements.
Logs reported to the Domain Dedicated Log Server can be viewed from any SmartConsole Check Point GUI application used to manage a Check Point environment - configure Security Policies, configure devices, monitor products and events, install updates, and so on. that has permissions for this Domain.
The Domain Dedicated Log Server communicates directly only with the associated Domain Server. No other Domain can access its log data.
Note - Connecting with SmartConsole to the Domain Dedicated Log Server to see Security Policies
Collection of rules that control network traffic and enforce organization guidelines for data protection and access to resources with packet inspection. is not supported.
For more information, see Deploying a Domain Dedicated Log Server.