Skip to content

Check Point Quantum Firewall

You can integrate Check Point Quantum Firewall with Sophos XDR so that it sends data to Sophos for analysis.

This page gives you an overview of the integration.

Check Point Quantum Firewall product overview

Check Point Quantum Firewall is an integrated network security gateway that delivers threat protection across the IT infrastructure, combining firewall, intrusion prevention, antivirus and anti-malware, threat emulation (sandboxing), application and URL control, VPN, and identity awareness, driven by real-time threat intelligence.

What we ingest

Sophos XDR collects Check Point Quantum Firewall data via syslog, exported from the Security Gateway (for example, using Check Point Log Exporter). Records are identified and parsed from the Common Event Format (CEF) and Log Extended Event Format (LEEF). The following log categories are collected:

  • Firewall connection traffic1: Per-session accept and drop records with source, destination, protocol, and port information.
  • Intrusion prevention and threat prevention: IPS and SmartDefense attack detections and threat emulation (sandboxing) events.
  • Antivirus and anti-malware: Malware and virus detections on traffic passing through the gateway, including email-borne malware.
  • Web and URL activity: HTTPS inspection and URL filtering records.
  • Authentication and identity awareness: VPN remote access and Mobile Access (Connectra) logon, logoff, and failure events; Identity Awareness AD Query mappings; and administrative authentication to SmartConsole and the management API.
  • Gateway and management logs1: General Security Gateway operational, system, and management activity.

Event and data types

We ingest the following event and data types from Check Point Quantum Firewall:

  • Firewall connection traffic1: Accepted and dropped sessions traversing the gateway. Normalized to netflow telemetry.
  • Intrusion and threat prevention: IPS/SmartDefense attack detections and threat emulation results. Normalized to third-party security alert telemetry.
  • Antivirus detections: Malware and virus detections on inspected traffic. Normalized to antivirus telemetry.
  • Email-borne malware: Malware detected in email traffic. Normalized to email telemetry.
  • Web and URL activity: HTTPS inspection and URL filtering events. Normalized to HTTP telemetry.
  • Authentication and identity awareness: VPN, Mobile Access, Identity Awareness, and administrative authentication events. Normalized to authentication telemetry.
  • Gateway and management logs1: General gateway, antivirus, SmartDefense, and SmartConsole activity records. Normalized to generic telemetry.

Data provided by this integration

Data provided by Check Point Quantum Firewall gets normalized to the following schemas:

  • antivirus
  • auth
  • email
  • generic 1
  • http
  • netflow 1
  • thirdpartyalert

For more information about using schemas in Data Lake Search, see Schemas and logical types.

Vendor documentation


  1. Netflow and generic telemetry are only available with a Sophos Next-Gen SIEM subscription. See Sophos Next-Gen SIEM overview