About The Device
Harmony Endpoint is a complete endpoint security solution built to protect the remote workforce from today’s complex threat landscape. It provides a 3600 endpoint protection with advanced EPP, EDR and XDR capabilities all in a single client.
Device Information
Entity | Particulars |
---|---|
Vendor Name | Check Point |
Product Name | Harmony Endpoint |
Type of Device | Hosted |
Collection Method
Log Type | Ingestion label | Preferred Logging Protocol | Log Collection Method |
---|---|---|---|
Check Point | CHECKPOINT_FIREWALL | Syslog (KV) | CyberHub |
Port Requirements
Source | Destination | Port |
---|---|---|
Check Point | CyberHub | 514 (UDP) |
Device Configuration
Navigate to Endpoint Settings > Export Events
Click Add
The New Logging Service window opens
Fill in the export details:
Name - Enter a name for the exported information.
IP Address - Enter the IP Address of the target to which the logs are exported.
Protocol - Select the protocol over which to export the logs: UDP.
Format - Select the Syslog format.
Port - Select the port over which to export the logs. Port - 514
Click Add.
TLS is only supported in case of Mutual Authentication that’s why TLS is not possible in our case so we will use UDP as protocol.
Integration Parameters
Parameters required from customer for Integration.
Property | Default Value | Description |
---|---|---|
IP Address | Check Point interface IP address | Hostname or IP address of the device which forwards logs to the CyberHub. |