Checkpoint Log integration with Microsoft Sentinel through Central Management Console

%3CLINGO-SUB%20id%3D%22lingo-sub-3017332%22%20slang%3D%22en-US%22%3ECheckpoint%20Log%20integration%20with%20Microsoft%20Sentinel%20through%20Central%20Management%20Console%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3017332%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20There%2C%3C%2FP%3E%3CP%3EOne%20of%20our%20client%20has%20multiple%20checkpoint%20firewalls%20connected%20to%20the%20central%20management%20console%20and%20was%20wondering%20if%20we%20can%20forward%20logs%20from%20the%20Checkpoint%20central%20management%20console%20to%20Microsoft%20sentinel.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EFrom%20the%20already%20available%20documentation%20and%20data%20connector%20available%20for%20checkpoint%20in%20MS%20Sentinel%2C%20I%20see%20only%20option%20for%20firewalls.%20Not%20sure%20if%20same%20is%20applicable%20for%20Central%20management%20console.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ECan%20one%20point%20to%20the%20right%20direction%20or%20provide%20any%20relevant%20reference.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%3C%2FP%3E%3CP%3EFahad.%3C%2FP%3E%3C%2FLINGO-BODY%3E
Contributor

Hi There,

One of our client has multiple checkpoint firewalls connected to the central management console and was wondering if we can forward logs from the Checkpoint central management console to Microsoft sentinel.

 

From the already available documentation and data connector available for checkpoint in MS Sentinel, I see only option for firewalls. Not sure if same is applicable for Central management console.

 

Can one point to the right direction or provide any relevant reference.

 

Thanks

Fahad.

1 Reply

@FahadAhmed I think you would need to check with Checkpoint to see if there is any way to get the data out of the console.  If it can, then it depends on how the data can be extracted.  If you are lucky, then it is just a matter of setting it up to go to a SysLog/CEF server.  If not, it may take some custom code to get the data.