- Products
- Learn
- Local User Groups
- Partners
- More
AI Security Masters E7:
How CPR Broke ChatGPT's Isolation and What It Means for You
Blueprint Architecture for Securing
The AI Factory & AI Data Center
Call For Papers
Your Expertise. Our Stage
Good, Better, Best:
Prioritizing Defenses Against Credential Abuse
Ink Dragon: A Major Nation-State Campaign
Watch HereCheckMates Go:
CheckMates Fest
Hi
We have a customer who is receiving emails from Checkpoint that their log ingestion rate is exceeding 50Gb and that they need to buy more storage.
This started from December - the log ingestion graph shows a flat line of nothing and then it explodes.
The customer is unaware of any changes in the environment.
It references two SK;
SK181096 - How to optimize cloud logs
SK182394 - Cloud log analytic & logging - ingestion/Retention solution.
For the second SK I'm not sure that customers have access to the product catalog(?)
For the first SK we followed the steps to identify the logs with a view to tuning the policy.
However when we filter as described we find that the logs are 100% Low Severity, 98.5% Event type update, 70.63% anti malware blade.
As such there is no matching rule so we cant follow the advice in the SK, we cant see how to prevent this log type from being ingested - does anyone have any ideas?
They are on E88.32.2003.
Thanks!
As a bit of background, EPMaaS tenants have a limit on the amount of logs that are allowed to be ingested.
We do not enforce these limits currently, but are expecting to start doing so by the end of Q1.
This is why you are starting to see notifications about it in Infinity Portal.
This is not 100% finalized, so the details might change.
More relevant to the accuracy of the notification itself, it appears (per TAC) the ingestion volume does not seem to be calculating correctly on all tenants.
This is under investigation.
yes, i will second that... starting about a week ago , we also started seeing this on some of our customers too. Sorry i dont have an answer for you.
thanks for confirming! nice to know its not isolated - well its not 'nice' its happening elsewhere but its at least a sanity check 🙂
We see exact the same this behavior. No change of the logs since a year, but now these messages. Something changed in the background ?
As a bit of background, EPMaaS tenants have a limit on the amount of logs that are allowed to be ingested.
We do not enforce these limits currently, but are expecting to start doing so by the end of Q1.
This is why you are starting to see notifications about it in Infinity Portal.
This is not 100% finalized, so the details might change.
More relevant to the accuracy of the notification itself, it appears (per TAC) the ingestion volume does not seem to be calculating correctly on all tenants.
This is under investigation.
We see this not not only for EPMaaS customer. Some Smart1-cloud tenants have the same behavior.
While I heard about this in the context of EPMaaS customers, Smart-1 Cloud customers also have similar limits that I assume will be enforced in the near future.
Noticed the same for 2 S1C cloud clients as well.
Andy
Noticed that as well in the portal for few customers.
Andy
Tue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFTue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFTue 12 May 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall delivered as a serviceThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY