Configure for Arctic Wolf Active Response

With the Active Response service, Arctic Wolf® can perform email-based response actions in your network using ®.

supports these response actions:

  • Quarantine an email/Remove from quarantine
For more information, see Response action descriptions.

These resources are required:

  • Administrator permissions for

Create a API key for Active Response

  1. Sign in to the https://portal.checkpoint.com/.
  2. Click New > New account API key.
  3. In the Create a New API Key window, configure these settings:
    • Service — Select Email Security.
    • Expiration — Set an expiration date.

      Check Point recommends setting the expiration to three months from the current date. It is possible, but not recommended, to create an API key without an expiration date.

      Note: If you set an expiration date, you must generate and refresh the credentials in the 統合ポータル before expiry.
    • (Optional) Description — Enter a descriptive name.
  4. Click Create.
  5. Copy the Client ID, Secret Key, and Authentication URL, and save them in a safe, encrypted location to provide to Arctic Wolf later.
  6. Click Close.

Provide Active Response credentials to Arctic Wolf

  1. Sign in to the Arctic Wolf Unified Portal.
  2. In the navigation menu, click Organization Profile > Integrations.
  3. On the Active Response tab, click New Active Response Integration +.
  4. Click Check Point Email Security.
  5. On the New Active Response Integration page, configure these settings:
    • Integration Name — Enter a unique and descriptive name for the integration.
    • Base URL — Enter the Authentication URL that you saved earlier. Remove /auth/external from the end of the URL.
    • Client ID — Enter the Client ID that you saved earlier.
    • Client Secret — Enter the Secret Key that you saved earlier.
    • Timeout — Select the number of hours Arctic Wolf should wait for a command response. Arctic Wolf recommends 1 hour.
  6. Click Save Integration.
  • Contact your CST to validate the Active Response integration. Have an account or environment ready that Arctic Wolf can use to validate the desired response actions without causing interruptions.