Check Point FW1/VPN1 ↗
You can configure collecting Check Point FW1/VPN1 logs using a Broker VM Syslog Collector applet, content pack integration (onboarded prior to July 26, 2026), or connector (onboarded after July 26, 2026):
| Collection Method | Description |
|---|---|
| Syslog Collector applet overview | If you use Check Point FW1/VPN1 firewalls, you can forward Check Point firewall logs to Cortex XSIAM using the Broker VM Syslog Collector applet in a CEF format. |
| Link to Syslog Collector applet instructions | Ingest logs from Check Point firewalls |
| Link to content pack/integration details (onboarded prior to July 26, 2026) | <p>The Check Point Firewall content pack manages Check Point firewall devices via API, allowing the reading information, sending commands, and orchestrating configuration and blocking actions. It contains a modeling rule (CheckPoint Firewall Collection) and several playbooks (for example Checkpoint - Block IP - Append Group, Checkpoint - Publish&Install configuration, Checkpoint - Block IP - Custom Block Rule, and Checkpoint - Block URL). It also includes the following integration:</p><ul><li>CheckPoint Firewall v2: Use this integration to read information and send commands to the Check Point Firewall server. It includes commands for handling threat protection and profiles, such as checkpoint-set-threat-protection and checkpoint-add-threat-profile.</li></ul> |
| Link to connector (onboarded after July 26, 2026) | Checkpoint Firewall |