- Products
- Learn
- Local User Groups
- Partners
- More
Secure Your AI Transformation
9 April @ 12pm SGT / 3pm CET / 2PM EDT
Check Point WAF TechTalk:
Introduction and New Features
AI Security Masters E6: When AI Goes Wrong -
Hallucinations, Jailbreaks, and the Curious Behavior of AI Agents
Ink Dragon: A Major Nation-State Campaign
Watch HereAI Security Masters E5:
Powering Prevention: The AI Driving Check Point’s ThreatCloud
CheckMates Go:
CheckMates Fest
Hello,
We currently have two domains.
1 Domain for DEV which has a MGT station, Firewall Cluster, and Log Server.
1 Domain for Prod which has 2 MGT staitons ( 1 is in HA ) 3 Firewall Clusters each with their own Log Server.
I have 3 questions. Our sales rep told us multi-domain is overkill.
Agent_Smith,
first of all I would like to send greetings from Neo...
Best solution for you will be using MultiDomain-Management. With this ou have separate management-domains, separate log servers, but you can see logs from both domains with one logviewer.
With your actual configuration you can't send logs from a gateway to a logserver in another management-domain. You need SIC beetween gateway and logserver and it's not possible to have more then one SIC-trust.
Another way to get the logs from both domains would be using a third party logserver. We had customer the are using SPLUNK. All gateways and management servers sends there logs via Log-Exporter Log Exporter - Check Point Log Export to the SPLUNK server. There is a nice CheckPoint app for splunk available, this gives you a similar view of the logs like in SmartConsole.
With Log-Exporter you can send your logs to any other Syslog-server not only splunk, maybee this is a solution for you.
Wolfgang
My understanding is that sending logs to Splunk or another syslog server limits the functionality of the logs because of the view. Can the Splunk App see traffic data?
I was told by the sales rep that independent of the SIC you can send logs from a firewall to a different log server. That SIC is only established between MGT and Firewalls.
Can we have more than 2 MGT stations on one domain?
Agent_Smith,
what dou you mean with „traffic data“ to shown in splunk?
There was a threat here for the splunk app New-Splunk-App-for-Check-Point-Logs
Yes, you can send logs from a gateway to more then one logserver, but they all have to be in the same domain.
Yes, you can have two management server, but they are running in HA, meaning one is active an the another one is standby.
Wolfgang
You can have only one management server and one HA management server per domain. But you can have more log servers.
In Check Points app for splunk you had a view like in smart event, but you can see the Check Point firewall raw logs in the normal splunk view.
Here is a copy of an example from https://weekly-geekly.github.io/articles/325170/index.html
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 67 | |
| 42 | |
| 20 | |
| 15 | |
| 13 | |
| 12 | |
| 11 | |
| 11 | |
| 9 | |
| 8 |
Tue 07 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Check Point WAF and IO River: Multi-CDN Security in ActionWed 08 Apr 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: The Cloud Firewall with near 100% Zero Day prevention - In 7 LanguagesWed 08 Apr 2026 @ 07:00 PM (CST)
ERM al Descubierto: Amenazas Ocultas que Pondrán a Prueba tu Empresa en 2026Tue 07 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Check Point WAF and IO River: Multi-CDN Security in ActionWed 08 Apr 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: The Cloud Firewall with near 100% Zero Day prevention - In 7 LanguagesWed 08 Apr 2026 @ 07:00 PM (CST)
ERM al Descubierto: Amenazas Ocultas que Pondrán a Prueba tu Empresa en 2026Tue 14 Apr 2026 @ 03:00 PM (PDT)
Renton, WA: Securing The AI Transformation and Exposure ManagementThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY