- Products
- Learn
- Local User Groups
- Partners
- More
Policy Insights and Policy Auditor in Action
19 November @ 5pm CET / 11am ET
Access Control and Threat Prevention Best Practices
Watch HereOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello,
We currently have two domains.
1 Domain for DEV which has a MGT station, Firewall Cluster, and Log Server.
1 Domain for Prod which has 2 MGT staitons ( 1 is in HA ) 3 Firewall Clusters each with their own Log Server.
I have 3 questions. Our sales rep told us multi-domain is overkill.
Agent_Smith,
first of all I would like to send greetings from Neo...
Best solution for you will be using MultiDomain-Management. With this ou have separate management-domains, separate log servers, but you can see logs from both domains with one logviewer.
With your actual configuration you can't send logs from a gateway to a logserver in another management-domain. You need SIC beetween gateway and logserver and it's not possible to have more then one SIC-trust.
Another way to get the logs from both domains would be using a third party logserver. We had customer the are using SPLUNK. All gateways and management servers sends there logs via Log-Exporter Log Exporter - Check Point Log Export to the SPLUNK server. There is a nice CheckPoint app for splunk available, this gives you a similar view of the logs like in SmartConsole.
With Log-Exporter you can send your logs to any other Syslog-server not only splunk, maybee this is a solution for you.
Wolfgang
My understanding is that sending logs to Splunk or another syslog server limits the functionality of the logs because of the view. Can the Splunk App see traffic data?
I was told by the sales rep that independent of the SIC you can send logs from a firewall to a different log server. That SIC is only established between MGT and Firewalls.
Can we have more than 2 MGT stations on one domain?
Agent_Smith,
what dou you mean with „traffic data“ to shown in splunk?
There was a threat here for the splunk app New-Splunk-App-for-Check-Point-Logs
Yes, you can send logs from a gateway to more then one logserver, but they all have to be in the same domain.
Yes, you can have two management server, but they are running in HA, meaning one is active an the another one is standby.
Wolfgang
You can have only one management server and one HA management server per domain. But you can have more log servers.
In Check Points app for splunk you had a view like in smart event, but you can see the Check Point firewall raw logs in the normal splunk view.
Here is a copy of an example from https://weekly-geekly.github.io/articles/325170/index.html
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 25 | |
| 14 | |
| 13 | |
| 8 | |
| 5 | |
| 4 | |
| 3 | |
| 3 | |
| 3 | |
| 2 |
Wed 19 Nov 2025 @ 11:00 AM (EST)
TechTalk: Improve Your Security Posture with Threat Prevention and Policy InsightsThu 20 Nov 2025 @ 05:00 PM (CET)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - AMERThu 20 Nov 2025 @ 10:00 AM (CST)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - EMEAWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchWed 19 Nov 2025 @ 11:00 AM (EST)
TechTalk: Improve Your Security Posture with Threat Prevention and Policy InsightsThu 20 Nov 2025 @ 05:00 PM (CET)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - AMERThu 20 Nov 2025 @ 10:00 AM (CST)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - EMEAThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY