Hi all,
We currently have dozens of Quantum Spark devices in the field and looking at a few comprehensive SIEM/SOAR/SOC solutions to enable comprehensive coverage across our clients environments.
Without purchasing Smart-1 for these clients (required for Check Point MDR integration), are we able to send syslogs to an external/internal collector (e.g., Adlumin collector, Huntress Agent)?
If this is possible, how is this achieved? Is it via disabling cloud services and then CLI? In your opinion, what is the down sides to disabling cloud services apart from managing firmware upgrades (currently via Infinity), policies etc.
I hope that makes sense and thanks for any assistance/guidance in advance.