본문으로 건너뛰기

Check Point Firewall Integration

Overview

Check Point firewalls provide enterprise-grade network security with integrated threat prevention, VPN, and access control. KYRA MDR collects Check Point logs via the Log Exporter utility for comprehensive security monitoring. Supports R80.x and R81.x versions.

Prerequisites

  • A KYRA MDR Collector installed and running
  • Check Point Security Management Server or standalone gateway
  • SmartConsole access for configuration
  • Log Exporter utility installed on the management server

Configuration

Configure Check Point Log Exporter:

  1. SSH into the Check Point Management Server
  2. Install and configure Log Exporter:
Terminal window
cp_log_export add name kyra-mdr \
target-server <collector-ip> \
target-port 514 \
protocol tcp \
format syslog \
read-mode semi-unified
  1. Start the exporter:
Terminal window
cp_log_export restart name kyra-mdr
  1. Verify status with cp_log_export status name kyra-mdr

Collected Log Types

Log TypeDescriptionSecurity Use
FirewallAccept/drop/reject decisionsNetwork policy enforcement, traffic analysis
IPSIntrusion prevention eventsExploit detection, vulnerability protection
Anti-BotBot detection and blockingC2 communication, botnet detection
Anti-VirusMalware detection eventsFile-based threat detection
Threat EmulationSandbox analysis resultsAdvanced persistent threat detection
VPNTunnel establishment and teardownRemote access monitoring

Troubleshooting

Log Exporter not sending: Run cp_log_export status name kyra-mdr to check the exporter state. Verify network connectivity to the collector.

Missing log fields: Ensure the Log Exporter format is set to syslog and the read mode is semi-unified for complete log data.

High latency: Check Point Log Exporter processes logs asynchronously. A delay of 1-2 minutes is normal under heavy load.

Contact kyra@seekerslab.com for support.