Check Point FW1/VPN1

You can configure collecting Check Point FW1/VPN1 logs using a Broker VM Syslog Collector applet, content pack integration (onboarded prior to July 26, 2026), or connector (onboarded after July 26, 2026):

| Collection Method | Description |
| --------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Syslog Collector applet overview | If you use Check Point FW1/VPN1 firewalls, you can forward Check Point firewall logs to Cortex XSIAM using the Broker VM Syslog Collector applet in a CEF format. |
| Link to Syslog Collector applet instructions | [Ingest logs from Check Point firewalls](../../generic-on-premise-data-collectors/broker-vm-data-collector-applets/syslog-collector-applet/check-point-fw1-vpn1/ingest-logs-from-check-point-firewalls) |
| Link to content pack/integration details (onboarded prior to July 26, 2026) | <p>The <a href="https://cortex.marketplace.pan.dev/marketplace/details/CheckpointFirewall/">Check Point Firewall</a> content pack manages Check Point firewall devices via API, allowing the reading information, sending commands, and orchestrating configuration and blocking actions. It contains a modeling rule (<strong><code>CheckPoint Firewall Collection</code></strong>) and several playbooks (for example Checkpoint - Block IP - Append Group, Checkpoint - Publish&#x26;Install configuration, Checkpoint - Block IP - Custom Block Rule, and Checkpoint - Block URL). It also includes the following integration:</p><ul><li><a href="https://xsoar.pan.dev/docs/reference/integrations/check-point-firewall-v2">CheckPoint Firewall v2</a>: Use this integration to read information and send commands to the Check Point Firewall server. It includes commands for handling threat protection and profiles, such as <strong><code>checkpoint-set-threat-protection</code></strong> and <strong><code>checkpoint-add-threat-profile</code></strong>.</li></ul> |
| Link to connector (onboarded after July 26, 2026) | [Checkpoint Firewall](checkpoint-firewall) |