Learn more about collecting Check Point FW1/VPN1 logs using a Syslog Collector applet and content pack integration in Cortex XSIAM.
You can configure collecting Check Point FW1/VPN1 logs using a Broker VM Syslog Collector applet or with a content pack integration:
Check Point FW1/VPN1 vendor | Description |
|---|---|
Syslog Collector applet overview | If you use Check Point FW1/VPN1 firewalls, you can forward Check Point firewall logs to Cortex XSIAM using the Broker VM Syslog Collector applet in a CEF format. |
Link to Syslog Collector applet instructions | |
Link to content pack/integration details | The Check Point Firewall content pack manages Check Point firewall devices via API, allowing the reading information, sending commands, and orchestrating configuration and blocking actions. It contains a modeling rule (
|