This integration is available on our Advanced and Enterprise packages.
Before you get started
This integration requires us to configure a collector on the edge of our network to receive your log data directly from Checkpoint Harmony. Before you get started, please reach out to our Technical Support team and make them aware that you're planning on setting up this integration.
They will then deploy the collector required for this and provide you with the IP address and certificates mentioned later in this guide. The certificates will come in an attachment on the support ticket containing 2 files: A *.pem Certificate Authority certificate and a *.p12 format client certificate.
Configuring Checkpoint Harmony
Log into the Harmony Endpoint for Checkpoint Harmony.
Go to Endpoint Settings and click Add.
The New Logging Service window will open:
Under Name select a name for the service eg. Defense logs.
Under IP address enter the IP address of your edge collector the support team has provided.
Under Protocol select UDP.
Under Format select Syslog.
Under Port select 514.
Under TLS/SSL select the checkbox and upload the certificates provided by the support team.
Save your changes.
Confirming log flow
Once the above steps are complete, your device will now ship logs to our SIEM platform via your collector. You can confirm logs are successfully reaching our SIEM by either.
Navigating to the Log Search feature in Defense.com by browsing to SIEM > Log Search and then filtering the logs by
type:"syslog".Reaching out to our Technical Support team, who'll be able to check and confirm this for you.
And that's it! You've successfully integrated Checkpoint Harmony🎉
