Check Point Firewall Integration
Overview
Check Point firewalls provide enterprise-grade network security with integrated threat prevention, VPN, and access control. KYRA MDR collects Check Point logs via the Log Exporter utility for comprehensive security monitoring. Supports R80.x and R81.x versions.
Prerequisites
- A KYRA MDR Collector installed and running
- Check Point Security Management Server or standalone gateway
- SmartConsole access for configuration
- Log Exporter utility installed on the management server
Configuration
Configure Check Point Log Exporter:
- SSH into the Check Point Management Server
- Install and configure Log Exporter:
cp_log_export add name kyra-mdr \ target-server <collector-ip> \ target-port 514 \ protocol tcp \ format syslog \ read-mode semi-unified- Start the exporter:
cp_log_export restart name kyra-mdr- Verify status with
cp_log_export status name kyra-mdr
Collected Log Types
| Log Type | Description | Security Use |
|---|---|---|
| Firewall | Accept/drop/reject decisions | Network policy enforcement, traffic analysis |
| IPS | Intrusion prevention events | Exploit detection, vulnerability protection |
| Anti-Bot | Bot detection and blocking | C2 communication, botnet detection |
| Anti-Virus | Malware detection events | File-based threat detection |
| Threat Emulation | Sandbox analysis results | Advanced persistent threat detection |
| VPN | Tunnel establishment and teardown | Remote access monitoring |
Troubleshooting
Log Exporter not sending: Run cp_log_export status name kyra-mdr to check the exporter state. Verify network connectivity to the collector.
Missing log fields: Ensure the Log Exporter format is set to syslog and the read mode is semi-unified for complete log data.
High latency: Check Point Log Exporter processes logs asynchronously. A delay of 1-2 minutes is normal under heavy load.
Contact kyra@seekerslab.com for support.