- Products
- Learn
- Local User Groups
- Partners
- More
Access Control and Threat Prevention Best Practices
5 November @ 5pm CET / 11am ET
Ask Check Point Threat Intelligence Anything!
October 28th, 9am ET / 3pm CET
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
Spark Management Portal and More!
Tomer,
I am seeing massive number of logs being generated for one of my users. It shows as Login>Logout>Logout>Login>Login>Update>Lather Rinse Repeat. This is happening EVERY SECOND!!
It has to be generating a lot of activity for your cloud service.
Can you attach the screenshot? I always work with 2 customers who use mgmt cloud server and I never seen this problem.
Andy
Wait a second...is this regarding specifically identity awareness?? The reason I ask is because I dont see it from smart-1 cloud instance, but harmony connect...I dont have that instance running for any customer, so cant say for sure.
What I am seeing is in the logs and events viewer of the beta. Just absolutely flooded with these entries.
I haven't done anything special. I do note that at this time it has stopped so I assume the user powered
down for the day. **Confirmed user shutdown laptop. Logging is looking more normal now. I assume when
he powers on tomorrow the flood will begin again.
what Identity source is this user using? Identity agent, regular AD query??
There is no AD involved. All I have done is create my beta account and send 3 users invites to install agents on 3 machines.
So I have exactly 3 accounts enrolled in the beta.
1 user laptop seems to be having an issue where it just floods the system with these login/logout/update requests all day.
Just to let @the_rock know, the Identity Awareness integration in Harmony Connect is different from what's supported on a traditional gateway.
It supports SAML providers (Azure AD, Okta, etc) directly and doesn't use the methods supported on a regular Check Point gateway.
Have you configured an Identity Provider at all?
Not that I am aware of. I just checked and I never activated it.
No idea why it started flooding me with Identity awareness logs.
Like I said when the guy shut his laptop down it stopped.
Have the user Collect Logs off the laptop (it's a button in the Harmony Connect app) and send them to @Tomer_Sole.
He'll probably contact you out-of-band tomorrow morning.
Will do.
Sorry brother, I figured it was something else, but was not sure...too many products :))
Trust me, I know 🙂
No apologies required! Have a pint my friend. It's St. Patty's Day!
Paging @Tomer_Sole
Indeed, if this is for a single end user, this should not happen, these many logs at the portal do not give a big value to the admin that sees them. And it could indicate on a potential problem with Harmony Connect App that runs on that single endpoint.
If this is for many end users connecting to the Internet at the same time then it's probably less of an issue, and you can use filters or start from the Access Control or Cyber-Attack View overview pages to drill down to the needed events.
Either way let's work this out as a support ticket. Check Point Support handles trials for cloud products as well. Harmony Connect for Users is in public beta but already supported by TAC. See exact steps for submitting support tickets for Harmony Connect at https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...
I will first work on replicating the issue and see if I can pinpoint the cause.
As there are frequent updates to the Harmony Connect app it could be something
that has already been resolved in an update. I will start by asking the end user to update
Harmony Connect to the latest version.
The client generally should auto-update.
If that's not happening, that's a different problem 🙂
Well, I have not seen it auto update on my system. I tend to open the app once in awhile to see if anything has changed and it has stated 'version update available'
or something along those lines a couple of times now. I clicked on it to update Connect. Maybe I am just catching it before it auto installs, I don't know.
In general we are monitoring end users that are active and contain an old version and contact the administrator of their account. The automatic updates happen behind the scenes. So if you weren't contacted, you should be fine
Tue 28 Oct 2025 @ 11:00 AM (EDT)
Under the Hood: CloudGuard Network Security for Google Cloud Network Security Integration - OverviewTue 28 Oct 2025 @ 12:30 PM (EDT)
Check Point & AWS Virtual Immersion Day: Web App ProtectionTue 28 Oct 2025 @ 11:00 AM (EDT)
Under the Hood: CloudGuard Network Security for Google Cloud Network Security Integration - OverviewTue 28 Oct 2025 @ 12:30 PM (EDT)
Check Point & AWS Virtual Immersion Day: Web App ProtectionThu 30 Oct 2025 @ 03:00 PM (CET)
Cloud Security Under Siege: Critical Insights from the 2025 Security Landscape - EMEAThu 30 Oct 2025 @ 11:00 AM (EDT)
Tips and Tricks 2025 #15: Become a Threat Exposure Management Power User!About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY