<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Checkpoint Harmony Endpoint in Endpoint</title>
    <link>https://community.checkpoint.com/t5/Endpoint/Checkpoint-Harmony-Endpoint/m-p/265574#M11137</link>
    <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am deploying url filtering in checkpoint harmony endpoint. I changed url filtering to prevent mode by selecting &amp;nbsp;categories in adv settings.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am getting only logs for block category/url not for allow url.&lt;/P&gt;&lt;P&gt;Is any configuration that need to be selected I am missing?&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Ankur&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 17 Dec 2025 17:48:21 GMT</pubDate>
    <dc:creator>an_technical</dc:creator>
    <dc:date>2025-12-17T17:48:21Z</dc:date>
    <item>
      <title>Checkpoint Harmony Endpoint</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Checkpoint-Harmony-Endpoint/m-p/265574#M11137</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am deploying url filtering in checkpoint harmony endpoint. I changed url filtering to prevent mode by selecting &amp;nbsp;categories in adv settings.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am getting only logs for block category/url not for allow url.&lt;/P&gt;&lt;P&gt;Is any configuration that need to be selected I am missing?&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Ankur&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Dec 2025 17:48:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Checkpoint-Harmony-Endpoint/m-p/265574#M11137</guid>
      <dc:creator>an_technical</dc:creator>
      <dc:date>2025-12-17T17:48:21Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint Harmony Endpoint</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Checkpoint-Harmony-Endpoint/m-p/265577#M11138</link>
      <description>&lt;P&gt;I asked Support AI Copilot this question and here's what it came back with:&lt;/P&gt;
&lt;H3&gt;1. Access the Policy Settings&lt;/H3&gt;
&lt;UL&gt;
&lt;LI&gt;Go to:&lt;BR /&gt;&lt;STRONG&gt;Policy → Threat Prevention → Web &amp;amp; Files Protection → Advanced settings&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3&gt;2. Enable Logging for Visited Sites&lt;/H3&gt;
&lt;UL&gt;
&lt;LI&gt;In the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Advanced settings&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;section, look for the option:
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Allow logs for visited sites&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;This checkbox is&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;not selected by default&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;to prevent generating excessive logs.&lt;/LI&gt;
&lt;LI&gt;Select (check) this option to log all visited (accepted) URLs.&lt;/LI&gt;
&lt;/UL&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;STRONG&gt;Note:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;This option may not be visible for all customers and is OFF by default.&lt;/LI&gt;
&lt;LI&gt;Enabling this on a large number of endpoints can overwhelm your management server. It is recommended to enable it only for a small group of endpoints if you are troubleshooting or need detailed visibility.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/BLOCKQUOTE&gt;
&lt;HR /&gt;
&lt;P&gt;A couple of notes about this:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;If you are managing your Endpoints via an on-prem management server, this can only be done in the Web interface (not SmartEndpoint).&lt;/LI&gt;
&lt;LI&gt;If you are using Infinity Portal, this will increase the log storage requirements in the cloud, particularly if it is enabled for a large user population.&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Wed, 17 Dec 2025 18:02:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Checkpoint-Harmony-Endpoint/m-p/265577#M11138</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-12-17T18:02:59Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint Harmony Endpoint</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Checkpoint-Harmony-Endpoint/m-p/265610#M11139</link>
      <description>&lt;P&gt;Not to compare AI copilot with MS copilot, but here is what MS one came up with (I choose think deeper setting, rather than auto or quick response, since we have fully licenses version)&lt;/P&gt;
&lt;P&gt;*********************************&lt;/P&gt;
&lt;DIV&gt;
&lt;H2&gt;What to change&lt;/H2&gt;
&lt;OL&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Enable logging for allowed URLs&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Go to: &lt;STRONG&gt;Policy → Threat Prevention → Web &amp;amp; Files Protection → Advanced settings&lt;/STRONG&gt;.&lt;/LI&gt;
&lt;LI&gt;Check the option &lt;STRONG&gt;“Allow logs for visited sites.”&lt;/STRONG&gt;&lt;BR /&gt;&lt;EM&gt;This is off by default to avoid massive log volumes.&lt;/EM&gt; &lt;A href="https://community.checkpoint.com/t5/Endpoint/Checkpoint-Harmony-Endpoint/td-p/265574" target="_blank" rel="noopener"&gt;[community....kpoint.com]&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Be aware of scope and UI&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;This setting is available in the &lt;STRONG&gt;web management&lt;/STRONG&gt; interface; it’s &lt;STRONG&gt;not in SmartEndpoint&lt;/STRONG&gt;. If you’re managing on‑prem via SmartEndpoint only, you won’t see it because &lt;STRONG&gt;URL Filtering is not supported with SmartEndpoint&lt;/STRONG&gt; (use the web UI/Infinity Portal). &lt;A href="https://community.checkpoint.com/t5/Endpoint/Checkpoint-Harmony-Endpoint/td-p/265574" target="_blank" rel="noopener"&gt;[community....kpoint.com]&lt;/A&gt;, &lt;A href="https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Harmony-Endpoint-Admin-Guide/Topics-HEP/Web-and-Files-Protection.htm" target="_blank" rel="noopener"&gt;[sc1.checkpoint.com]&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;(Optional) Cover non‑browser traffic&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;In the same &lt;STRONG&gt;Advanced settings → URL Filtering&lt;/STRONG&gt; area, consider enabling &lt;STRONG&gt;“Network URL Filtering”&lt;/STRONG&gt; so URLs opened by applications/processes (not just browsers) are also inspected and logged. &lt;A href="https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Harmony-Endpoint-Admin-Guide/Topics-HEP/Web-and-Files-Protection.htm" target="_blank" rel="noopener"&gt;[sc1.checkpoint.com]&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;HR /&gt;
&lt;H2&gt;Why you currently see only “block” logs&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;In &lt;STRONG&gt;Prevent&lt;/STRONG&gt; mode, Harmony Endpoint stops access to selected categories and &lt;STRONG&gt;logs the block&lt;/STRONG&gt;. Allowed traffic isn’t logged unless you enable &lt;EM&gt;Allow logs for visited sites&lt;/EM&gt;. &lt;A href="https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Harmony-Endpoint-Admin-Guide/Topics-HEP/Web-and-Files-Protection.htm" target="_blank" rel="noopener"&gt;[sc1.checkpoint.com]&lt;/A&gt;, &lt;A href="https://community.checkpoint.com/t5/Endpoint/Checkpoint-Harmony-Endpoint/td-p/265574" target="_blank" rel="noopener"&gt;[community....kpoint.com]&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;Switching a category to &lt;STRONG&gt;Detect&lt;/STRONG&gt; will &lt;STRONG&gt;log detections&lt;/STRONG&gt; while allowing access, but it &lt;STRONG&gt;doesn’t produce full “allow” visibility&lt;/STRONG&gt; across all benign sites. The “Allow logs for visited sites” checkbox is what gives comprehensive allow logs. &lt;A href="https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Harmony-Endpoint-Admin-Guide/Topics-HEP/Web-and-Files-Protection.htm" target="_blank" rel="noopener"&gt;[sc1.checkpoint.com]&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;HR /&gt;
&lt;H2&gt;Where to see the logs (and forward them)&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Infinity Portal → Harmony Endpoint Logs&lt;/STRONG&gt; provides filters, views, and CSV export for endpoint events. &lt;A href="https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Harmony-Endpoint-Admin-Guide/Topics-HEP/Logs-menu.htm" target="_blank" rel="noopener"&gt;[sc1.checkpoint.com]&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Infinity Events&lt;/STRONG&gt; offers a unified events view (including Harmony Endpoint) with customizable columns and 90‑day default retention. &lt;A href="https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/IOC-Admin-Guide/Content/Common-Topics/Events-Logs.htm" target="_blank" rel="noopener"&gt;[sc1.checkpoint.com]&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;If you need to &lt;STRONG&gt;send these logs to a SIEM&lt;/STRONG&gt;, set up &lt;STRONG&gt;Event Forwarding&lt;/STRONG&gt; from Infinity Portal (Push to SIEM or Azure storage). &lt;A href="https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Infinity-Portal-Admin-Guide/Content/Topics-Infinity-Portal/Event-Forwarding.htm" target="_blank" rel="noopener"&gt;[sc1.checkpoint.com]&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;HR /&gt;
&lt;H2&gt;Practical tips &amp;amp; cautions&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Start small:&lt;/STRONG&gt; Enabling allow‑logs for all endpoints can overwhelm storage/ingestion. Enable it for a &lt;STRONG&gt;test group&lt;/STRONG&gt; first to gauge volume. &lt;A href="https://community.checkpoint.com/t5/Endpoint/Checkpoint-Harmony-Endpoint/td-p/265574" target="_blank" rel="noopener"&gt;[community....kpoint.com]&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Browser plugin dependency:&lt;/STRONG&gt; The Harmony Endpoint &lt;STRONG&gt;browser extension (SBA plugin)&lt;/STRONG&gt; is used to gain full visibility into HTTP/HTTPS traffic; make sure it’s present (especially on Chrome/Edge). &lt;A href="https://community.checkpoint.com/t5/Product-Announcements/Endpoint-Security-SandBlast-Agent-Newsletter-Version-E83-10/ba-p/89640" target="_blank" rel="noopener"&gt;[community....kpoint.com]&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Policy coverage:&lt;/STRONG&gt; Double‑check your &lt;STRONG&gt;selected categories&lt;/STRONG&gt; (and any &lt;STRONG&gt;deny list&lt;/STRONG&gt; entries/wildcards) in &lt;STRONG&gt;Advanced settings → URL Filtering&lt;/STRONG&gt; so your configuration matches your intent. &lt;A href="https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Harmony-Endpoint-Admin-Guide/Topics-HEP/Web-and-Files-Protection.htm" target="_blank" rel="noopener"&gt;[sc1.checkpoint.com]&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/DIV&gt;</description>
      <pubDate>Thu, 18 Dec 2025 01:57:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Checkpoint-Harmony-Endpoint/m-p/265610#M11139</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-12-18T01:57:23Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint Harmony Endpoint</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Checkpoint-Harmony-Endpoint/m-p/265613#M11140</link>
      <description>&lt;P&gt;Okay. I don't see this option so its look like its off by default as I am using cloud portal.&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Dec 2025 06:13:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Checkpoint-Harmony-Endpoint/m-p/265613#M11140</guid>
      <dc:creator>an_technical</dc:creator>
      <dc:date>2025-12-18T06:13:25Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint Harmony Endpoint</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Checkpoint-Harmony-Endpoint/m-p/265677#M11141</link>
      <description>&lt;P&gt;Open a TAC case: &lt;A href="https://help.checkpoint.com" target="_blank"&gt;https://help.checkpoint.com&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Dec 2025 16:03:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Checkpoint-Harmony-Endpoint/m-p/265677#M11141</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-12-18T16:03:42Z</dc:date>
    </item>
  </channel>
</rss>

