Configure for Arctic Wolf monitoring

You can configure ® to send the necessary logs to Arctic Wolf® for security monitoring. This integration provides Arctic Wolf with data about email security events and activity in your organization.

These resources are required:

  • Administrator permissions for the

Obtain Email & Collaboration API credentials from

Generate an Email & Collaboration API key in the to provide to Arctic Wolf as the Events API credentials.

  1. In the https://portal.checkpoint.com/, select API Keys from the left navigation panel.
  2. In the Create a New API Key window, configure these settings:
    • Service — Select Email & Collaboration.
    • Expiration — Select an expiration date and time for the API key.

      Check Point recommends setting the expiration date to three months from the present date. It is possible, but not recommended, to create an API key without an expiration date.

      Note: If you set an expiration date, you must generate and refresh the credentials in the Portail unifié before expiry.
    • (Optional) Description — Enter a description for the API key.
  3. Click Create.
    The generates a new API key.
  4. Copy the Client ID, Secret Key, and Authentication URL, and save them in a safe, encrypted location to provide to Arctic Wolf as the Events API credentials.
  5. Click Close.

Obtain API credentials from

Generate an Infinity Portal API key in the to provide to Arctic Wolf as the Audit Logs API credentials.

  1. In the https://portal.checkpoint.com/, select API Keys from the left navigation panel.
  2. Click New > New account API key.
  3. In the Create a New API Key window, configure these settings:
    • Service — Select Infinity Portal.
    • Expiration — Select an expiration date and time for the API key.

      Check Point recommends setting the expiration date to three months from the present date. It is possible, but not recommended, to create an API key without an expiration date.

      Note: If you set an expiration date, you must generate and refresh the credentials in the Portail unifié before expiry.
    • (Optional) Description — Enter a description for the API key.
    • Roles — Select the Read-only checkbox.
  4. Click Create.
    The generates a new API key.
  5. Copy the Client ID, Secret Key, and Authentication URL, and save them in a safe, encrypted location to provide to Arctic Wolf as the Audit Logs API credentials.
  6. Click Close.

Provide credentials to Arctic Wolf

  1. Connectez-vous à Portail unifié Arctic Wolf.
  2. In the navigation menu, click Data Collection > Cloud Sensors.
  3. Click Add Account +.
  4. On the Add Account page, click Check Point Email Security.
  5. Configure these settings:
    • Account Name — Enter a unique and descriptive name for the account.

    • API URL — Select the region that matches the Authentication URL from the Email & Collaboration API key.
    • Events API Client ID — Enter the Client ID for the Email & Collaboration service generated in Obtain Email & Collaboration API credentials from .
    • Events API Access Key — Enter the Secret Key for the Email & Collaboration service generated in Obtain Email & Collaboration API credentials from .
    • Audit Logs API Client ID — Enter the Client ID for the Infinity Portal service generated in Obtain API credentials from .
    • Audit Logs API Access Key — Enter the Secret Key for the Infinity Portal service generated in Obtain API credentials from .
    • Credential Expiry — Enter the credential expiration date, if applicable.

  6. Click Test and submit credentials.