Configure Check Point Email Security for Arctic Wolf monitoring

You can configure Check Point Email Security® to send the necessary logs to Arctic Wolf® for security monitoring. This integration provides Arctic Wolf with data about email security events and activity in your organization.

These resources are required:

  • Administrator permissions for the Check Point Portal

Obtain Email & Collaboration API credentials from Check Point Email Security

Generate an Email & Collaboration API key in the Check Point Portal to provide to Arctic Wolf as the Events API credentials.

  1. In the Check Point Portal, select API Keys from the left navigation panel.
  2. In the Create a New API Key window, configure these settings:
    • Service — Select Email & Collaboration.
    • Expiration — Select an expiration date and time for the API key.

      Check Point recommends setting the expiration date to three months from the present date. It is possible, but not recommended, to create an API key without an expiration date.

      Note: If you set an expiration date, you must generate and refresh the credentials in the Unified Portal before expiry.
    • (Optional) Description — Enter a description for the API key.
  3. Click Create.
    The Check Point Portal generates a new API key.
  4. Copy the Client ID, Secret Key, and Authentication URL, and save them in a safe, encrypted location to provide to Arctic Wolf as the Events API credentials.
  5. Click Close.

Obtain Check Point Portal API credentials from Check Point Email Security

Generate an Infinity Portal API key in the Check Point Portal to provide to Arctic Wolf as the Audit Logs API credentials.

  1. In the Check Point Portal, select API Keys from the left navigation panel.
  2. Click New > New account API key.
  3. In the Create a New API Key window, configure these settings:
    • Service — Select Infinity Portal.
    • Expiration — Select an expiration date and time for the API key.

      Check Point recommends setting the expiration date to three months from the present date. It is possible, but not recommended, to create an API key without an expiration date.

      Note: If you set an expiration date, you must generate and refresh the credentials in the Unified Portal before expiry.
    • (Optional) Description — Enter a description for the API key.
    • Roles — Select the Read-only checkbox.
  4. Click Create.
    The Check Point Portal generates a new API key.
  5. Copy the Client ID, Secret Key, and Authentication URL, and save them in a safe, encrypted location to provide to Arctic Wolf as the Audit Logs API credentials.
  6. Click Close.

Provide Check Point Email Security credentials to Arctic Wolf

  1. Sign in to the Arctic Wolf Unified Portal.
  2. In the navigation menu, click Data Collection > Cloud Sensors.
  3. Click Add Account +.
  4. On the Add Account page, click Check Point Email Security.
  5. Configure these settings:
  6. Click Test and submit credentials.