OPSEC/LEA log source parameters for Check Point Multi-Domain Management (Provider-1)

If QRadar does not automatically detect the log source, add a Check Point Multi-Domain Management (Provider-1) log source on the QRadar Console by using the OPSEC/LEA protocol.

When using the OPSEC/LEA protocol, there are specific parameters that you must use.

The following table describes the parameters that require specific values to collect OPSEC/LEA events from Check Point Multi-Domain Management (Provider-1):
Table 1. OPSEC/LEA log source parameters for the Check Point Multi-Domain Management (Provider-1) DSM
Parameter Value
Log Source type Check Point
Protocol Configuration OPSEC/LEA
Log Source Identifier Type the IP address for the log source.

This value must match the value that you typed in the Server IP parameter.

For a complete list of OPSEC/LEA protocol parameters and their values, see OPSEC/LEA protocol configuration options.