- Products
- Learn
- Local User Groups
- Partners
- More
Call For Papers
Your Expertise, Our Stage
Ink Dragon: A Major Nation-State Campaign
Watch HereAI Security Masters E5:
Powering Prevention: The AI Driving Check Point’s ThreatCloud
The Great Exposure Reset
AI Security Masters E4:
Introducing Cyata, Securing the Agentic AI Era
CheckMates Go:
CheckMates Fest
I am in search for a document related to OPSEC configuration in checkpoint to integrate with 3rd party SIEM tools. Kindly share documents if any.
Maybe you can search from 3rd SIEM that you need to integrate with CheckPoint.
Like this.
Hi Sangeeth,
Are you after anything in particular? As the options you select on the OPSEC configuration may differ per product.
Or are you after a quick how to setup an OPSEC configuration?
As Kosin Usuwanthim has advised the 3rd party should have a guide on how to integrate their product with Check Point.
Regards
Mark
Hi Mark
Yes, we are using ArcSight.
But the actual issue that we are facing is that "User" field is shown as "Confidential" in logs (Clear connection is configured).
I also gone through sk101570 (3rd Scenario) which is related to our issue. I hope by following the given procedure will solve this issue. Kindly suggest...
Reference : sk101570
Some fields in logs on 3rd party LEA OPSEC client show "*** Confidential ***"
Hi Sangeeth,
Within your OPSEC configuration do you have the LEA configuration settings set to "Hide all confidential log fields"? This will cause what you are seeing.

if you can post your OPSEC configuration we can take a look and advise as necessary.
Regards
Mark
Hi Mark
As stated in earlier comment , the connection type configured is "clear" in ArcSight. I believe that we need not to create an OPSEC application for clear connection.
Regards
Sangeeth
Sounds like you're on the right track as far as the LEA options. Let us know how it works out for you.
Hi Bob
I had performed the same :
But the issue is still persisting. "Target User Name " filed in logs received in ArcSight is still showing as ***confidential ***.
More over the Management Server is running on GAIA Windows OS R77.30.
Dameon Welch-Abernathy Kindly suggest.
I suggest a TAC case.
Maybe use Log Exporter instead?
Log Exporter is used only in R80.* version and not in R77 or below version .
Please correct me if i am wrong .
You can get Log Exporter for R77.30, but R77.30 and earlier releases are End of Support.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 35 | |
| 22 | |
| 17 | |
| 12 | |
| 9 | |
| 9 | |
| 8 | |
| 8 | |
| 8 | |
| 7 |
Tue 17 Mar 2026 @ 03:00 PM (CET)
From SASE to Hybrid Mesh: Securing Enterprise AI at Scale - EMEATue 17 Mar 2026 @ 02:00 PM (EDT)
From SASE to Hybrid Mesh: Securing Enterprise AI at Scale - AMERWed 18 Mar 2026 @ 10:00 AM (CET)
The Cloud Architects Series: An introduction to Check Point Hybrid Mesh in 2026 - In Seven LanguagesThu 19 Mar 2026 @ 11:00 AM (EDT)
Tips and Tricks 2026 #2: AI Security Challenges and SolutionsTue 17 Mar 2026 @ 03:00 PM (CET)
From SASE to Hybrid Mesh: Securing Enterprise AI at Scale - EMEATue 17 Mar 2026 @ 02:00 PM (EDT)
From SASE to Hybrid Mesh: Securing Enterprise AI at Scale - AMERWed 18 Mar 2026 @ 10:00 AM (CET)
The Cloud Architects Series: An introduction to Check Point Hybrid Mesh in 2026 - In Seven LanguagesThu 19 Mar 2026 @ 11:00 AM (EDT)
Tips and Tricks 2026 #2: AI Security Challenges and SolutionsTue 24 Mar 2026 @ 04:00 PM (CET)
Maestro Masters EMEA: Hyperscale Firewall Architectures and OptimizationTue 24 Mar 2026 @ 06:00 PM (COT)
San Pedro Sula: Spark Firewall y AI-Powered Security ManagementThu 26 Mar 2026 @ 06:00 PM (COT)
Tegucigalpa: Spark Firewall y AI-Powered Security ManagementAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY