Cette page n'est pas encore disponible en français, sa traduction est en cours. Si vous avez des questions ou des retours sur notre projet de traduction actuel, n'hésitez pas à nous contacter.
Check Point Next Generation Firewall is a security gateway that includes application control and IPS protection, with integrated management of security events. Additional features include Identity Awareness, URL Filtering, Anti-Bot, Anti-Virus, and Anti-Spam.
This integration ingests URL Filtering logs, Anti Bot logs, Application Control, Firewall, Identity Awareness, IPS, Threat Emulation, and miscellaneous event types with the integration log pipeline to enrich the logs and normalizes data to Datadog standard attributes. This integration offers dashboard visualizations with detailed insights into allowed or blocked URLs, bot details, insights into accessed application data, events generated by firewall, mapping between computer identities and machine IP address, and more.
Configure Syslog Message Forwarding from Checkpoint Quantum Firewall:
Connect to the command line on the Management Server / Log Server.
Login to the Expert mode. Enter your administrative credentials (after entering credentials, expert mode is enabled).
In order to configure a new target for the exported logs, enter the following commands:
cp_log_export add name <Name of Log Exporter Configuration> target-server <HostName or IP address of Target Server> target-port <Port on Target Server> protocol {tcp | udp} format json
In the commands above, specify the following Syslog Server Details:
name: The Name of the syslog server. For example: datadog_syslog.
target-server: The destination where you want to send the Checkpoint Quantum Firewall logs.
target-port: The port on which the syslog server is listening (typically 514).
protocol: The protocol name, or which protocol will be used to send logs (TCP/UDP).
format: Format must be ‘json’.
In order to save and add the syslog server configuration, use the following command:
cp_log_export restart name <Name of Log Exporter Configuration>
The Checkpoint Quantum Firewall integration collects Firewall, URL Filtering, IPS, Identity Awareness, Application Control, Threat Emulation, Audit, Anti Ransomware, Anti Spam & Email Security, Anti Exploit, Anti Bot, Anti Virus, HTTPS Inspection, DLP, and Anti Malware logs.
If you see the Port <PORT-NO> Already in Use error, see the following instructions. The example below is for PORT-NO = 514:
On systems using Syslog, if the Agent listens for Checkpoint Quantum Firewall logs on port 514, the following error can appear in the Agent logs: Can't start UDP forwarder on port 514: listen udp :514: bind: address already in use.
This error occurs because by default, Syslog listens on port 514. To resolve this error, take one of the following steps:
Disable Syslog
Configure the Agent to listen on a different, available port