Check Point FW1/VPN1
Use Check Point FW1/VPN1 data with Cortex Cloud.
You can configure collecting Check Point FW1/VPN1 logs using a Broker VM Syslog Collector applet or content pack integration (onboarded prior to July 26, 2026):
Syslog Collector applet overview
If you use Check Point FW1/VPN1 firewalls, you can forward Check Point firewall logs to Cortex Cloud using the Broker VM Syslog Collector applet in a CEF format.
Link to Syslog Collector applet instructions
Link to content pack/integration details (onboarded prior to July 26, 2026)
The Check Point Firewall content pack manages Check Point firewall devices via API, allowing the reading information, sending commands, and orchestrating configuration and blocking actions. It contains a modeling rule (CheckPoint Firewall Collection) and several playbooks (for example Checkpoint - Block IP - Append Group, Checkpoint - Publish&Install configuration, Checkpoint - Block IP - Custom Block Rule, and Checkpoint - Block URL). It also includes the following integration:
CheckPoint Firewall v2: Use this integration to read information and send commands to the Check Point Firewall server. It includes commands for handling threat protection and profiles, such as
checkpoint-set-threat-protectionandcheckpoint-add-threat-profile.
Last updated
Was this helpful?
