Check Point Email Security (via Codeless Connector Framework)

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Connectors Index


Attribute Value
Connector ID CheckPointEmailSecConnector
Publisher Microsoft
Used in Solutions Checkpoint Email Security
Collection Method CCF
Connector Definition Files CheckPointEmailSecurity_ConnectorDefinition.json
DCR Definition Files CheckPointEmailSecurity_DCR.json
CCF Configuration CheckPointEmailSecurity_PollerConfig.json
CCF Capabilities JwtToken, Paging, POST

The Check Point Email Security (Harmony Email Collaboration) data connector provides the capability to ingest security events and audit logs from Check Point's Email Security platform into Microsoft Sentinel through the REST API. The connector provides visibility into advanced email threats including zero-day threats, phishing, account takeover, data leakage, and shadow IT discovery. It ingests security events, anti-phishing exceptions, spam exceptions, and audit logs into Microsoft Sentinel, helping organizations maintain security and compliance visibility.

Tables Ingested

This connector ingests data into the following tables:

Table Transformations Ingestion API Lake-Only
CheckPointEmailSecAntiPhishingExceptions_CL ? ?
CheckPointEmailSecurityAuditLogs_CL ? ?
CheckPointEmailSecurityEvents_CL ? ?
CheckPointEmailSecuritySpamExceptions_CL ? ?

💡 Tip: Tables with Ingestion API support allow data ingestion via the Azure Monitor Data Collector API, which also enables custom transformations during ingestion.

Permissions

Resource Provider Permissions:

Custom Permissions:

Setup Instructions

⚠️ Note: These instructions were automatically generated from the connector's user interface definition file using AI and may not be fully accurate. Please verify all configuration steps in the Microsoft Sentinel portal.

1. Connect Check Point Email Security to Microsoft Sentinel To gather data from Check Point Email Security, you need to provide the following credentials: 1. API Base URL - The base URL for your Check Point Email Security tenant (region-specific). 2. Client ID - Client ID of the Harmony Email & Collaboration API key (used for security events and exceptions). 3. Client Secret - Secret (access key) of the Harmony Email & Collaboration API key. 4. Audit Client ID - Client ID of a separate Logs as a Service API key (used for audit logs). 5. Audit Client Secret - Secret (access key) of the Logs as a Service API key. To obtain these credentials, log in to your Check Point Infinity Portal and navigate to the API Keys section under Global Settings. Create one API key with the Harmony Email & Collaboration service for the Client ID/Secret, and a second API key with the Logs as a Service service for the Audit Client ID/Secret.

Multi-tenant support: This connector supports ingesting data from multiple Check Point Email Security tenants in parallel. Click Add Connection once per tenant, supplying that tenant's API Base URL and credentials - each connection is tracked and managed independently in the grid below. Connector Management Interface

This section is an interactive interface in the Microsoft Sentinel portal that allows you to manage your data collectors.

📊 View Existing Collectors: A management table displays all currently configured data collectors with the following information:

Add New Collector: Click the "Add new collector" button to configure a new data collector (see configuration form below).

🔧 Manage Collectors: Use the actions menu to delete or modify existing collectors.

💡 Portal-Only Feature: This configuration interface is only available when viewing the connector in the Microsoft Sentinel portal. You cannot configure data collectors through this static documentation.

Configure Check Point Email Security API Connection

Connect to Check Point Email Security to ingest security data

When you click the "Add Connection" button in the portal, a configuration form will open. You'll need to provide:

💡 Portal-Only Feature: This configuration form is only available in the Microsoft Sentinel portal.


Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Connectors Index