Hi we have this working.
did you enable host port scan in IPS as per
https://support.checkpoint.com/results/sk/sk110873
then you need to enabled smart event to see the events occuring.
if you use the sam rule you want to do this also.
Connect with SmartDashboard to Security Management Server / Domain Management Server.
Open the relevant Security Gateway / Cluster object.
Expand 'Other' - go to 'SAM' pane - check the box 'Purge SAM file when it reaches:' - set the desired limit - click in 'OK'.
Notes: The minimal size is 50 KB.
Save the changes: go to 'File' menu - click on 'Save'.
Install the policy onto relevant Security Gateway / Cluster object.
Thanks
Frank