Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Mitja-S3NEXT
Collaborator
Jump to solution

What is the default LOG retention period in a Harmony Endpoint Advanced license?

What is the default LOG retention period in a Harmony Endpoint Advanced license?

(LOG, not AUDIT LOG)

1 Solution

Accepted Solutions
Mitja-S3NEXT
Collaborator

SK and admin guide for more information: 

1. Audit Logs

  • Retention Period: Audit logs in Infinity Portal are kept for a minimum of one year (12 months), regardless of license.
  • Reference:

    "Audit logs are kept on record for a minimum of one year."
    (Infinity Portal Administration Guide)

2. Operational/Event Logs (All Other Logs)

  • Retention Period:
    • The default and guaranteed retention period for operational/event logs (including security events, endpoint activity, etc.) is determined by your Harmony Endpoint license.
    • For most standard licenses, this period is 90 days.
  • What Happens After Retention Period?
    • After the retention period (e.g., 90 days), logs are deleted and cannot be recovered from the Infinity Portal.
    • There is no official documentation confirming that operational/event logs are kept longer than the licensed retention period, even if you see some logs older than 90 days in the UI. This may be due to backend processing delays or exceptions, but you should not guarantee longer retention to customers.

3. NIS2 Compliance (180 Days)

  • Requirement: NIS2 requires all logs (not just audit) to be retained for at least 180 days.
  • Check Point Guarantee:
    • Unless you have a specific license or agreement for 180-day retention, Check Point only guarantees the retention period defined in your license (typically 90 days).
    • If you need to guarantee 180 days, you must:
      • Upgrade your license to a plan that supports 180-day retention (if available).
      • Export logs regularly to external storage (e.g., SIEM, Azure Storage, etc.) for long-term retention.

4. Forwarding/Exporting Logs

  • Infinity Portal allows forwarding logs to external storage (e.g., Azure Storage), but note:
    • The storage account retains data for only 7 days by default (unless you configure longer retention on your storage solution).
    • You are responsible for managing retention in external systems.


Check Point guarantees log retention for the period defined in your license. For most customers, this is 90 days for all operational/event logs and 1 year for audit logs. If you require 180-day retention for NIS2 compliance, you must either upgrade your license or regularly export your logs to an external system for long-term storage.
 

View solution in original post

21 Replies
the_rock
MVP Diamond
MVP Diamond

Im fairly sure its 90 days.

Best,
Andy
"Have a great day and if its not, change it"
0 Kudos
Mitja-S3NEXT
Collaborator

No, thats surely not.
I can see LOGs from 2023. But what I need to know is the exact limitation.

0 Kudos
the_rock
MVP Diamond
MVP Diamond

I was thinking of something else then. Lets see if someone can confirm for sure. Maybe if you check with Account services, they might be able to verify as well.

Best,
Andy
"Have a great day and if its not, change it"
0 Kudos
Mitja-S3NEXT
Collaborator

That would be very nice.

0 Kudos
the_rock
MVP Diamond
MVP Diamond

If I were you, would call Account services folks, just give them your UC account number and Im positive they will give you the right info. I always find them to be extremely helpful when I call.

Best,
Andy
"Have a great day and if its not, change it"
0 Kudos
Chris_Atkinson
MVP Platinum CHKP MVP Platinum CHKP
MVP Platinum CHKP

Correct 90 days is default (for Cloud Managed) per:

https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Harmony-Endpoint-Admin-Guide/...

CCSM R77/R80/ELITE
0 Kudos
Mitja-S3NEXT
Collaborator
 

Any idea, why I see LOGs from 2023, I attached a screenshot?
Maybe I forgot to mention it is the CLOUD version of Endpoint.

 

Chris_Atkinson
MVP Platinum CHKP MVP Platinum CHKP
MVP Platinum CHKP

Do you have any of the retention license extensions in place per: sk182394 ?

CCSM R77/R80/ELITE
0 Kudos
Mitja-S3NEXT
Collaborator

No, everything is default, the license is Harmony Endpoint Advanced,

0 Kudos
PhoneBoy
Admin
Admin

I would check with TAC on this, honestly. 

0 Kudos
the_rock
MVP Diamond
MVP Diamond

Hey mate,

Were you able to find the answer to this?

Best,
Andy
"Have a great day and if its not, change it"
0 Kudos
Mitja-S3NEXT
Collaborator

Unfortunately not.

0 Kudos
the_rock
MVP Diamond
MVP Diamond

Did you open Account services case?

Best,
Andy
"Have a great day and if its not, change it"
0 Kudos
Mitja-S3NEXT
Collaborator

It is a sales related technical question. 

0 Kudos
the_rock
MVP Diamond
MVP Diamond

I would still see if Account services would know, if not, they can refere you to your SE.

Best,
Andy
"Have a great day and if its not, change it"
0 Kudos
Mitja-S3NEXT
Collaborator

I opened now a TAC, i will keep this post updated.

the_rock
MVP Diamond
MVP Diamond

Please keep us posted.

Best,
Andy
"Have a great day and if its not, change it"
0 Kudos
Mitja-S3NEXT
Collaborator

This is the TAC response:

----------------------------------------------------------------------

Thank you for contacting Check Point Account Services.

Please note that while Account Services is happy to assist with any licensing and/or User Center related issues, we are a post-sales team only and therefore do not handle sale related issues.

 

0 Kudos
the_rock
MVP Diamond
MVP Diamond

K, so then I suppose only other logical option would be your local SE.

Best,
Andy
"Have a great day and if its not, change it"
0 Kudos
Mitja-S3NEXT
Collaborator

SK and admin guide for more information: 

1. Audit Logs

  • Retention Period: Audit logs in Infinity Portal are kept for a minimum of one year (12 months), regardless of license.
  • Reference:

    "Audit logs are kept on record for a minimum of one year."
    (Infinity Portal Administration Guide)

2. Operational/Event Logs (All Other Logs)

  • Retention Period:
    • The default and guaranteed retention period for operational/event logs (including security events, endpoint activity, etc.) is determined by your Harmony Endpoint license.
    • For most standard licenses, this period is 90 days.
  • What Happens After Retention Period?
    • After the retention period (e.g., 90 days), logs are deleted and cannot be recovered from the Infinity Portal.
    • There is no official documentation confirming that operational/event logs are kept longer than the licensed retention period, even if you see some logs older than 90 days in the UI. This may be due to backend processing delays or exceptions, but you should not guarantee longer retention to customers.

3. NIS2 Compliance (180 Days)

  • Requirement: NIS2 requires all logs (not just audit) to be retained for at least 180 days.
  • Check Point Guarantee:
    • Unless you have a specific license or agreement for 180-day retention, Check Point only guarantees the retention period defined in your license (typically 90 days).
    • If you need to guarantee 180 days, you must:
      • Upgrade your license to a plan that supports 180-day retention (if available).
      • Export logs regularly to external storage (e.g., SIEM, Azure Storage, etc.) for long-term retention.

4. Forwarding/Exporting Logs

  • Infinity Portal allows forwarding logs to external storage (e.g., Azure Storage), but note:
    • The storage account retains data for only 7 days by default (unless you configure longer retention on your storage solution).
    • You are responsible for managing retention in external systems.


Check Point guarantees log retention for the period defined in your license. For most customers, this is 90 days for all operational/event logs and 1 year for audit logs. If you require 180-day retention for NIS2 compliance, you must either upgrade your license or regularly export your logs to an external system for long-term storage.
 

the_rock
MVP Diamond
MVP Diamond

Thanks for updating us!

Best,
Andy
"Have a great day and if its not, change it"

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events