Hi,
No, we didn't succeed in solving that problem.
We used a Network Access Control (NAC) server as the source of the syslog messages.
I believe that the IC server expects to receive the following events:
Authentication events - 4624, 4768, 4769, 4770
Group update events - 4728, 4729, 4732, 4733, 4756, 4757
Group deletion events - 4730, 4734, 4758
Source: https://support.checkpoint.com/results/sk/sk108235
Our NAC server did not generate any such events. Therefore, our testing ended with a negative result.