IBM QRadar

IBM QRadar

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  Qradar and checkpoint endpoint protection logs

    Posted Thu May 26, 2022 07:00 AM
    Hello people,

    I have another question because i was not able to find it here if someone asked.. I wanted to ask if there is a way to implement the checkpoint endpoint protection logs that can be read on the smartconsole into the qradar log feed? I want to do that because i want to see everything in one console and want to make some offense events that will notify me via e-mail. Just to be clear we do not have the checkpoint firewall but the checkpoint endpoint protection.

    Thank you very much.

    ------------------------------
    Slavcho Andreevski
    ------------------------------


  • 2.  RE: Qradar and checkpoint endpoint protection logs

    Posted Fri May 27, 2022 02:30 AM
    Hi Slavcho

    DSM guide from page 495 , it describe Check Point log source configuration But no see checkpoint endpoint protection product.
    http://public.dhe.ibm.com/software/security/products/qradar/documents/iTeam_addendum/b_dsm_guide.pdf

    If current Check Point DSM not support endpoint log parsing, you may need to use Universal DSM

    ------------------------------
    Brian Kwak
    ------------------------------