- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026
Inception is On!
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Improve Your Security Posture with
Threat Prevention and Policy Insights
Overlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
How to configure alert for identity collector for below condition.
customer is having both R80.10 and R77.30 version gateway.
I'm afraid I can't give you full script as it is fully integrated into our own in-house monitoring system so it wouldn't make much sense
but to give you an idea assuming you have multiple IDCs (else you can take away while loop)
currTime=`date +%s`
pdp conn idc | grep ^[1-9] > idc.tmp
while read line; do
if [ `echo $line | grep -c "No events received in the last hour" ` -eq 0 ]; then
lastEvent=`echo $line | awk '{print $5" "$6}'`
lastEvent=`date --date="$lastEvent" +%s`
let diff=$currTime-$lastEvent
if [ $diff -gt 120 ]; then
do something here if no events seen in last 2 minutes
fi
fi
done < idc.tmp
I could not imagine how to do that. But what i know is that Identity Collector is using the Windows Event Log API for fetching DC´s security logs. And if you know that these conditions show up in logs, you can use SmartEvent for alerting.
We have scripted it and are checking update timestamp against current time. Then issue alert if nothing arrives in X minutes depending on the time of the day

It really depends what sort of alert you want to generate. Custom SNMP traps are described here
Hello Kasparas,
would you be so kind and share scripts please?
or navigate us further where to focus please?
thanks,
Juraj
I'm afraid I can't give you full script as it is fully integrated into our own in-house monitoring system so it wouldn't make much sense
but to give you an idea assuming you have multiple IDCs (else you can take away while loop)
currTime=`date +%s`
pdp conn idc | grep ^[1-9] > idc.tmp
while read line; do
if [ `echo $line | grep -c "No events received in the last hour" ` -eq 0 ]; then
lastEvent=`echo $line | awk '{print $5" "$6}'`
lastEvent=`date --date="$lastEvent" +%s`
let diff=$currTime-$lastEvent
if [ $diff -gt 120 ]; then
do something here if no events seen in last 2 minutes
fi
fi
done < idc.tmp
Thank you Kasparas very much...really helpful...
Thanks Kasparas ,Its really helpful .
CP has released better monitoring capability for identity collector in R80.20. If you look at sk108235 at the 'Monitoring Capability' section, you can get more details.
Basically, you have to enable it on the identity collector server in the registry by adding a key called 'MonitoringEnabled'. Once enabled, it will send stats from IDC to the attached gateways / PDPs. You can view that info from the CLI using:
You can also monitor these items via SNMP on the gateway:
Hope that helps.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 22 | |
| 17 | |
| 8 | |
| 7 | |
| 6 | |
| 6 | |
| 6 | |
| 5 | |
| 5 | |
| 4 |
Wed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY