TEAM: Huntress Managed Security Information and Event Management (SIEM)
PRODUCT: SIEM Syslog
ENVIRONMENT: Check Point
SUMMARY: Configuration Guide for Check Point firewalls
Vendor Information
| Vendor | Check Point Software Technologies |
| Supported Model Name/Number | Quantum Security Gateway, managed via a Check Point Management Server / SmartConsole |
| Supported Software Version(s) | R81, R81.10, R81.20, R82 |
| Collection Method | Syslog |
| Provider Name | Syslog-Check Point |
| Additional Information |
Log Exporter Administration Guide (PDF) Log Exporter Configuration in CLI |
Please note that Huntress provides third-party vendor instructions as a best effort to expedite onboarding. Vendor documentation and versions frequently change, and so it may be necessary to find the appropriate documentation for syslog logging for your version of the vendor software or service.
Device Configuration Checklist
Check Point ships logs to third-party SIEM tools via its Log Exporter feature, configured on the Management Server (or a dedicated Log Server/CLM if traffic logs are split off), not on the individual Security Gateway.
Confirm Log Exporter is available
- Log Exporter ships with R80.20 and later Management Servers. On earlier versions, install the Jumbo Hotfix that introduces the
cp_log_exportcommand.
Create a Log Exporter target
- Connect to the Management Server via SSH and enter Expert mode, then run:
cp_log_export add name Huntress-SIEM target-server <Huntress Agent IP> target-port 514 protocol udp format cef
| Name | Any identifying name (for example, Huntress-SIEM) |
| Target-Server | Internal IP or FQDN of the Huntress Agent |
| Target-Port | 514 |
| Protocol | UDP (Huntress SIEM is not compatible with TLS or encrypted syslog) |
| Format | CEF |
Alternatively, this can be configured from SmartConsole under:
- Manage & Settings > Blades > Logging & Status > Log Exporter using the same values.
Restart Log Exporter
- Run:
cp_log_export restart
Confirm Log Flow
- Verify that the target status shows as running and connected by running:
cp_log_export show
Example Log Messages
Firewall Traffic Log Message
<134>1 2026-09-21T15:54:05Z checkpoint-mgmt CheckPoint - - - CEF:0|Check Point|VPN-1 & FireWall-1|R81.20|Log|Log|Unknown|act=Accept rt=Sep 21 2026 15:54:05 spt=52341 dpt=443 proto=6 src=10.0.0.2 dst=10.0.0.3 in=ethernet1/2 out=ethernet1/1 cs1Label=Rule Name cs1=Outbound-Internet cs2Label=Rule UID cs2=ba6a1e7e-2f6d-4b1a-9d8a-9a2f8a1e6c2d ifdir=inbound ifname=eth1 loguid={0x66f1a2c3,0x1,0xc0a80102,0xc0000001}
Threat Prevention Log Message
<134>1 2026-09-21T15:55:12Z checkpoint-mgmt CheckPoint - - - CEF:0|Check Point|Threat Prevention|R81.20|Anti-Bot|Trojan detected|Critical|act=Detect rt=Sep 21 2026 15:55:12 src=10.0.0.5 dst=203.0.113.9 proto=6 cs1Label=Protection Name cs1=Generic Trojan Communication cs2Label=Confidence Level cs2=High cs3Label=Malware Family cs3=Generic.Trojan resource=trojan-c2.example.net