sk154872 - Microsoft Sentinel / Azure Log Analytics: Example configuration for Cloud Firewall and on-premises Check Point appliances
Microsoft Sentinel / Azure Log Analytics: Example configuration for Cloud Firewall and on-premises Check Point appliances
Product: Cloud Firewall, Security Gateways, Smart-1 Cloud
Version: R81 (EOS), R81.10 (EOS), R81.20, R82, R82.10
Last Modified: 2026-05-11
Solution
Introduction
Microsoft Azure is a full-featured cloud platform with many useful management features included as standard or for a fee.
This document describes how to send traffic and audit logs from a Check Point Management environment (Security Management Server or Multi-Domain Management Server) to Azure for processing into the Microsoft toolchain.
Note: This document assumes that you have "contributor" or "owner" access to the subscription. This may not be true in a tightly controlled enterprise Azure subscription. Address any issues with permissions to your Azure subscription owner or ask Microsoft Azure support for help.
The Check Point documentation for Log Exporter is available at: sk122323 - Log Exporter - Check Point Log Export
The Azure portal has a detailed workflow for enabling the service.
Topology
The solution topology is for Check Point Management, whether on-premises or in the cloud, to send data to a Microsoft Sentinel Workspace using a Linux CEF agent installed on a separate VM. (The Linux VM can be on-premises or in the Cloud.)
Direct Check Point Management and Microsoft Sentinel communication are not possible.
Notes:
If the traffic from the Check Point Management to Linux agent goes over the Internet, the log traffic should ideally be encrypted with TLS. This is not in the scope of this document. For instructions refer to sk122323 - Log Exporter.
It can take 20 minutes for the Check Point traffic and audit logs to start appearing in Sentinel.
How to send Check Point logs to Microsoft Sentinel
Starting from August 31, 2024 Microsoft Sentinel retired the previous Log Analytics agent, and you must configure all log forwarding on the new Azure Monitor Agent.
The new Azure Monitor Agent
- Simpler management with Data Collection Rule
- 25% higher throughput
- Azure or On-Premises (Requires Azure ARC)
For more information, refer to the Azure Monitor Agent documentation.
Note: This solution applies to Check Point Security Management Server, Multi-Domain Security Management Server and Smart-1 Cloud only. For Harmony SASE refer to:
Architecture diagram
Configuration Steps
Configure Microsoft Sentinel
Create new CEF Data Connector: In the Azure Portal, go to Microsoft Sentinel > Content management > Content hub, search for Common Event Format and click Install.
Configure the new Data Connector: In the Azure Portal, go to Microsoft Sentinel > Configuration > Data connectors > Common Event Format (CEF) via AMA and open the connector page.
In the Basic tab, input rule name.
In the Resources tab, select the CEF Collector to install the agent on.
Note: If the CEF Collector is not installed in Azure, add it to Azure ARC. Refer to step 2.2 below.
In the Collect tab, set all Facility Minimum log level to LOG_DEBUG.
in the Review + create tab, review the settings and create the Data Collection Rule.
Install Azure Monitor Agent on CEF Collector
Copy the installation command and apply the CEF collector.
- After the agent installation, it fetches the data collection rules automatically.
- Future data collection rule updates also apply to the agent automatically.
Add CEF collector to Azure ARC: Note: Skip this step if a collector is installed in Azure. Why must the Azure Arc Connected Machine agent be installed to use Azure Monitor Agent? Azure Monitor Agent authenticates to your workspace through managed identity, which is created when you install the Connected Machine agent. Managed Identity is a more secure and manageable authentication solution from Azure. The legacy Log Analytics agent used the workspace ID and key to authenticate, so it did not need Azure Arc.
In the Azure Portal, go to Azure Arc > Azure Arc resources > Machines > Add/Create > Add a machine > Add multiple servers > Generate script.
Download the on-boarding script.
Update the on-boarding script with service principle secret.
Copy and run the on-boarding script on CEF Collector.
Make sure that the CEF Collector is on-boarded to Azure ARC: Take note of the resource group and name for next step.
Refer to step 2.a to complete the installation of Azure Monitor Agent.
Configure Check Point Security Management and Smart-1 Cloud
Configure Log Export on Check Point Security Management Server:
Connect to the command line on the Security Management Server.
Log in to the Expert mode.
Run:
cp_log_export add name syslog-forwarder target-server <CEF Collector IP address> target-port 514 protocol tcp format cefcp_log_export restartConfigure Log Export on Smart-1 Cloud: Open Infinity portal https://portal.checkpoint.com > Smart-1 Cloud > Settings > Advanced > Forward to SIEM > New.
Verification and Troubleshooting
Run a Microsoft Sentinel Query. From the Azure Portal, go to Microsoft Sentinel > Logs > Tables > Microsoft Sentinel > CommonSecurityLog.
Example output of Check Point firewall logs in Microsoft Sentinel:
To make sure that logs from the Security Management or Smart-1 Cloud are logging the to CEF collector, run this command from the collector:
sudo netstat -planvt | grep 514To make sure that AMA is running correctly on the CEF collector, run the command:
sudo wget -O Sentinel_AMA_troubleshoot.py https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/DataConnectors/Syslog/Sentinel_AMA_troubleshoot.py&&sudo python Sentinel_AMA_troubleshoot.py --cef
For the latest Azure Monitor Agent (AMA) troubleshooting commands, refer to this link.
NOTE
This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.