Check Point FW1/VPN1

You can configure collecting Check Point FW1/VPN1 logs using a Broker VM Syslog Collector applet, content pack integration (onboarded prior to July 26, 2026), or connector (onboarded after July 26, 2026):

Collection Method Description
Syslog Collector applet overview If you use Check Point FW1/VPN1 firewalls, you can forward Check Point firewall logs to Cortex XSIAM using the Broker VM Syslog Collector applet in a CEF format.
Link to Syslog Collector applet instructions Ingest logs from Check Point firewalls
Link to content pack/integration details (onboarded prior to July 26, 2026) <p>The Check Point Firewall content pack manages Check Point firewall devices via API, allowing the reading information, sending commands, and orchestrating configuration and blocking actions. It contains a modeling rule (CheckPoint Firewall Collection) and several playbooks (for example Checkpoint - Block IP - Append Group, Checkpoint - Publish&Install configuration, Checkpoint - Block IP - Custom Block Rule, and Checkpoint - Block URL). It also includes the following integration:</p><ul><li>CheckPoint Firewall v2: Use this integration to read information and send commands to the Check Point Firewall server. It includes commands for handling threat protection and profiles, such as checkpoint-set-threat-protection and checkpoint-add-threat-profile.</li></ul>
Link to connector (onboarded after July 26, 2026) Checkpoint Firewall