Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
| Attribute | Value |
|---|---|
| Connector ID | CheckPointEmailSecConnector |
| Publisher | Microsoft |
| Used in Solutions | Checkpoint Email Security |
| Collection Method | CCF |
| Connector Definition Files | CheckPointEmailSecurity_ConnectorDefinition.json |
| DCR Definition Files | CheckPointEmailSecurity_DCR.json |
| CCF Configuration | CheckPointEmailSecurity_PollerConfig.json |
| CCF Capabilities | JwtToken, Paging, POST |
The Check Point Email Security (Harmony Email Collaboration) data connector provides the capability to ingest security events and audit logs from Check Point's Email Security platform into Microsoft Sentinel through the REST API. The connector provides visibility into advanced email threats including zero-day threats, phishing, account takeover, data leakage, and shadow IT discovery. It ingests security events, anti-phishing exceptions, spam exceptions, and audit logs into Microsoft Sentinel, helping organizations maintain security and compliance visibility.
This connector ingests data into the following tables:
| Table | Transformations | Ingestion API | Lake-Only |
|---|---|---|---|
CheckPointEmailSecAntiPhishingExceptions_CL |
? | ✓ | ? |
CheckPointEmailSecurityAuditLogs_CL |
? | ✓ | ? |
CheckPointEmailSecurityEvents_CL |
? | ✓ | ? |
CheckPointEmailSecuritySpamExceptions_CL |
? | ✓ | ? |
💡 Tip: Tables with Ingestion API support allow data ingestion via the Azure Monitor Data Collector API, which also enables custom transformations during ingestion.
Resource Provider Permissions:
Custom Permissions:
⚠️ Note: These instructions were automatically generated from the connector's user interface definition file using AI and may not be fully accurate. Please verify all configuration steps in the Microsoft Sentinel portal.
1. Connect Check Point Email Security to Microsoft Sentinel To gather data from Check Point Email Security, you need to provide the following credentials: 1. API Base URL - The base URL for your Check Point Email Security tenant (region-specific). 2. Client ID - Client ID of the Harmony Email & Collaboration API key (used for security events and exceptions). 3. Client Secret - Secret (access key) of the Harmony Email & Collaboration API key. 4. Audit Client ID - Client ID of a separate Logs as a Service API key (used for audit logs). 5. Audit Client Secret - Secret (access key) of the Logs as a Service API key. To obtain these credentials, log in to your Check Point Infinity Portal and navigate to the API Keys section under Global Settings. Create one API key with the Harmony Email & Collaboration service for the Client ID/Secret, and a second API key with the Logs as a Service service for the Audit Client ID/Secret.
Multi-tenant support: This connector supports ingesting data from multiple Check Point Email Security tenants in parallel. Click Add Connection once per tenant, supplying that tenant's API Base URL and credentials - each connection is tracked and managed independently in the grid below. Connector Management Interface
This section is an interactive interface in the Microsoft Sentinel portal that allows you to manage your data collectors.
📊 View Existing Collectors: A management table displays all currently configured data collectors with the following information:
➕ Add New Collector: Click the "Add new collector" button to configure a new data collector (see configuration form below).
🔧 Manage Collectors: Use the actions menu to delete or modify existing collectors.
💡 Portal-Only Feature: This configuration interface is only available when viewing the connector in the Microsoft Sentinel portal. You cannot configure data collectors through this static documentation.
Configure Check Point Email Security API Connection
Connect to Check Point Email Security to ingest security data
When you click the "Add Connection" button in the portal, a configuration form will open. You'll need to provide:
💡 Portal-Only Feature: This configuration form is only available in the Microsoft Sentinel portal.
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊