- Products
- Learn
- Local User Groups
- Partners
- More
Firewall Uptime, Reimagined
How AIOps Simplifies Operations and Prevents Outages
Introduction to Lakera:
Securing the AI Frontier!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
Hi,
I am setting up an Identity Collector in our CP environment. I have one question regarding the number of events. In the Identity Collector dashboard I can see the number of events being sent, and through the Gateway CLI we can see also the number of events, but these two numbers do not correlate with each other. Is this an expected behavior?
I'm sending the examples below.
Identity Collector:
Gateway CLI:
have you enabled the monitoring feature on IDC side? (check "Monitoring capability" section under sk108235)
Hi @Hrvoje_Brlek,
I don't remember the calculation behind "pdp conn idc" event counter, but probably there is a logic to unify the events for same user&IP (while the UI for sure doesn't unify them).
To see the same output as the IDC UI, you can use "pdp idc status" (R80.30 and above) or "cpstat identityServer -f idc"
Hi,
When I run those commands, this is the output I get:
The same output is on a Gateway running 80.40 JHF T83 and on 80.30 JHF T219.
Am I doing something wrong?
There is no connectivity issues between Identity Collector and the Gateways (both VSX), nor are there any firewalls on the way. Identity collector version is the latest one from CP, it has configured six DCs, with all of them generating events visible through IC dashboard.
Why not have TAC resolve this ? Does not look healthy...
Already have a few TAC cases open. Would really like not to have to open a TAC case for every minor change or implementation in a Check Point environment. 😐
But, if necessary will do so...
have you enabled the monitoring feature on IDC side? (check "Monitoring capability" section under sk108235)
Works like a charm, thank you very much 😊
Grateful that no TAC was necessary 😉
Hi @Hrvoje_Brlek ,
I have same problem in R80.30 take 255. Since I enabled IDC and removed Ad Query (wmi access denied since last patch for windows server), the "Source User Name" field is not displayed on the logs tab. As a result, some policies are not being matched. In IDC side everything seems fine:
# pdp idc status
Identity Collector IP: X.X.X.X
Identity Sources:
No information about identity sources
pdp conn idc
Number of IDCollector sessions: 1
------------------------------------------------------------------------------------------------------------
# IP Number of events Shared secret status Last Event
------------------------------------------------------------------------------------------------------------
1 x.x.x.x Valid No events received in the last hour
¿How to fix?
Regards
Hi @daniextremo, this was a post from a few years ago, but as I recall I followed the section "Monitoring Capability" in sk108235 and it helped -> you need to add the Registry Key on the IDC server (Windows machine).
Thanks for reply @Hrvoje_Brlek . I could fix the problem.
Regards!
hello @daniextremo , How did you solve your problem, I have the same problem in a load sharing cluster R81.10
hello @daniextremo , How did you solve the problem?, I have the same problem with a cluster
Hi @bcalderon ,
I don't remember exactly, but it's very likely that it was solved by adding the registry key that @Hrvoje_Brlek mention.
I see that registry key exists in my server.
Identity Collector - Send Monitoring Information
Regards
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
24 | |
13 | |
9 | |
8 | |
8 | |
6 | |
5 | |
4 | |
4 | |
4 |
Wed 22 Oct 2025 @ 11:00 AM (EDT)
Firewall Uptime, Reimagined: How AIOps Simplifies Operations and Prevents OutagesWed 22 Oct 2025 @ 11:00 AM (EDT)
Firewall Uptime, Reimagined: How AIOps Simplifies Operations and Prevents OutagesTue 28 Oct 2025 @ 11:00 AM (EDT)
Under the Hood: CloudGuard Network Security for Google Cloud Network Security Integration - OverviewAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY