sk154872 - Microsoft Sentinel / Azure Log Analytics: Example configuration for Cloud Firewall and on-premises Check Point appliances

Microsoft Sentinel / Azure Log Analytics: Example configuration for Cloud Firewall and on-premises Check Point appliances

Product: Cloud Firewall, Security Gateways, Smart-1 Cloud
Version: R81 (EOS), R81.10 (EOS), R81.20, R82, R82.10
Last Modified: 2026-05-11

Solution

Introduction

Microsoft Azure is a full-featured cloud platform with many useful management features included as standard or for a fee.

This document describes how to send traffic and audit logs from a Check Point Management environment (Security Management Server or Multi-Domain Management Server) to Azure for processing into the Microsoft toolchain.

Note: This document assumes that you have "contributor" or "owner" access to the subscription. This may not be true in a tightly controlled enterprise Azure subscription. Address any issues with permissions to your Azure subscription owner or ask Microsoft Azure support for help.

The Check Point documentation for Log Exporter is available at: sk122323 - Log Exporter - Check Point Log Export

The Azure portal has a detailed workflow for enabling the service.

Topology

The solution topology is for Check Point Management, whether on-premises or in the cloud, to send data to a Microsoft Sentinel Workspace using a Linux CEF agent installed on a separate VM. (The Linux VM can be on-premises or in the Cloud.)

Direct Check Point Management and Microsoft Sentinel communication are not possible.

Notes:

How to send Check Point logs to Microsoft Sentinel

Starting from August 31, 2024 Microsoft Sentinel retired the previous Log Analytics agent, and you must configure all log forwarding on the new Azure Monitor Agent.

The new Azure Monitor Agent

For more information, refer to the Azure Monitor Agent documentation.

Note:  This solution applies to Check Point Security Management Server, Multi-Domain Security Management Server and Smart-1 Cloud only. For Harmony SASE refer to:

Architecture diagram

Configuration Steps

  1. Configure Microsoft Sentinel

  2. Create new CEF Data Connector: In the Azure Portal, go to Microsoft Sentinel > Content management > Content hub, search for Common Event Format and click Install.

  3. Configure the new Data Connector: In the Azure Portal, go to Microsoft Sentinel > Configuration > Data connectors > Common Event Format (CEF) via AMA and open the connector page.

  4. In the Basic tab, input rule name.

  5. In the Resources tab, select the CEF Collector to install the agent on.

    Note: If the CEF Collector is not installed in Azure, add it to Azure ARC. Refer to step 2.2 below.

  6. In the Collect tab, set all Facility Minimum log level to LOG_DEBUG.

  7. in the Review + create tab, review the settings and create the Data Collection Rule.

  8. Install Azure Monitor Agent on CEF Collector

  9. Copy the installation command and apply the CEF collector.

    • After the agent installation, it fetches the data collection rules automatically.
    • Future data collection rule updates also apply to the agent automatically.
  10. Add CEF collector to Azure ARC: Note: Skip this step if a collector is installed in Azure. Why must the Azure Arc Connected Machine agent be installed to use Azure Monitor Agent? Azure Monitor Agent authenticates to your workspace through managed identity, which is created when you install the Connected Machine agent. Managed Identity is a more secure and manageable authentication solution from Azure. The legacy Log Analytics agent used the workspace ID and key to authenticate, so it did not need Azure Arc.

    1. In the Azure Portal, go to Azure Arc > Azure Arc resources > Machines > Add/Create > Add a machine > Add multiple servers > Generate script.

    2. Download the on-boarding script.

    3. Update the on-boarding script with service principle secret.

    4. Copy and run the on-boarding script on CEF Collector.

    5. Make sure that the CEF Collector is on-boarded to Azure ARC: Take note of the resource group and name for next step.

    6. Refer to step 2.a to complete the installation of Azure Monitor Agent.

  11. Configure Check Point Security Management and Smart-1 Cloud

  12. Configure Log Export on Check Point Security Management Server:

    1. Connect to the command line on the Security Management Server.

    2. Log in to the Expert mode.

    3. Run:

      cp_log_export add name syslog-forwarder target-server <CEF Collector IP address> target-port 514 protocol tcp format cef

      cp_log_export restart

    4. Configure Log Export on Smart-1 Cloud: Open Infinity portal https://portal.checkpoint.com > Smart-1 Cloud > Settings > Advanced > Forward to SIEM > New.

  13. Verification and Troubleshooting

  14. Run a Microsoft Sentinel Query. From the Azure Portal, go to Microsoft Sentinel > Logs > Tables > Microsoft Sentinel > CommonSecurityLog.

Example output of Check Point firewall logs in Microsoft Sentinel:

  1. To make sure that logs from the Security Management or Smart-1 Cloud are logging the to CEF collector, run this command from the collector:

    sudo netstat -planvt | grep 514

  2. To make sure that AMA is running correctly on the CEF collector, run the command:

    sudo wget -O Sentinel_AMA_troubleshoot.py https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/DataConnectors/Syslog/Sentinel_AMA_troubleshoot.py&&sudo python Sentinel_AMA_troubleshoot.py --cef

For the latest Azure Monitor Agent (AMA) troubleshooting commands, refer to this link.

NOTE

This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.