Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
dehaasm
Collaborator
Jump to solution

Cloudguard Azure Smartevents

We have a VMSS cluster deployed in Azure with SMS, now we are looking to deploy a seperate Smartevents server in Azure.

What would be the best way to implement the Smartevent solution in Azure and integrate it into the current CME/SMS configuration? Is there a Azure template available and some documentation?

0 Kudos
1 Solution

Accepted Solutions
PhoneBoy
Admin
Admin

There isn't a template for management configuration, generally speaking.
You would spin up a new management instance with just SmartEvent installed.
Or, you can also add SmartEvent to your existing management VM, though you might want to spin up a larger instance if you go that route.

View solution in original post

11 Replies
PhoneBoy
Admin
Admin

There isn't a template for management configuration, generally speaking.
You would spin up a new management instance with just SmartEvent installed.
Or, you can also add SmartEvent to your existing management VM, though you might want to spin up a larger instance if you go that route.

dehaasm
Collaborator

we decided to enable smartevent on the SMS, so we can simply enable the blade Smartevent server on the SMS in Azure?

0 Kudos
PhoneBoy
Admin
Admin

Assuming you have a license for it, yes.

0 Kudos
Bryan-Smith
Employee
Employee

@dehaasm  as @PhoneBoy mentioned there is no specific template for an Azure SmartEvent server. I would definitely recommend spinning up a separate SmartEvent server using premium SSD for the IOPS.

In Azure you can select the Check Point Security Management template then chose to configure manually. (See screenshot below) At this point you would follow the traditional setup instructions with the first time wizard (FTW).

azure-mp-option.png

 

It's worth noting that MDS has an installation type that is specific to the log server setup. (mds-logserver)

 

0 Kudos
dehaasm
Collaborator

Hi Bryan,

Thanks for sharing your knowledge. At the moment we have management server+smartevents license on single SMS IP, would it be possible to transfer the Smartevent license/component to the dedicated smartevents server with the new IP address?

Bryan-Smith
Employee
Employee

@dehaasm that is a good question. I would double check with your account team to make sure you are licensed to run a dedicated SmartEvent server. I believe you need to have a dedicated SmartEvent server license to split it out.

0 Kudos
dehaasm
Collaborator

Hi Bryan,

We want to install Smartevent server on the same SMS what would you recommend for the system requriements, we currently have 4 CPU / 16GB mem and the there are about 150 log events per second.

0 Kudos
PhoneBoy
Admin
Admin

That is the configuration I use for my lab installation of SMS+SmartEvent, which I consider a bare minimum installation.
It should suffice as a starting point, but doesn't give you a ton of headroom.

0 Kudos
dehaasm
Collaborator

should we go for 8CPU with 32GB RAM doubling it?

0 Kudos
PhoneBoy
Admin
Admin

If it were me, I would.

0 Kudos
Bryan-Smith
Employee
Employee

@dehaasm 8 vCPU / 32GB RAM is a great starting point to run the correlation unit. 

High Level Overview of Event Identification (checkpoint.com)

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.