↳ GitHub sourceConnector

Check Point Email Security (via Codeless Connector Framework)

Description

The [Check Point Email Security (Harmony Email Collaboration)](https://www.checkpoint.com/harmony/email-security/) data connector provides the capability to ingest security events and audit logs from Check Point's Email Security platform into Microsoft Sentinel through the REST API. The connector provides visibility into advanced email threats including zero-day threats, phishing, account takeover, data leakage, and shadow IT discovery. It ingests security events, anti-phishing exceptions, spam exceptions, and audit logs into Microsoft Sentinel, helping organizations maintain security and compliance visibility.
Declared status
1
Declared author / publisher
Microsoft

Declared sources

Metadata from the source file. No dependencies inferred from KQL.

Data types

Declared permissions

Read and Write permissions are required.
Workspace
Workspace
Check Point Email Security API Credentials
Two separate Check Point Infinity Portal API keys are required. A **Harmony Email & Collaboration** API key (**Client ID** + **Client Secret**) is used for security events and exceptions. A separate **Logs as a Service** API key (**Audit Client ID** + **Audit Client Secret**) is required for audit logs. Generate both from your Check Point Infinity Portal under Global Settings > API Keys.

Connector instructions

Content published in the repository. Refer to the original file for all parameters.

Connect Check Point Email Security to Microsoft Sentinel
Add Connection
Configure Check Point Email Security API Connection
API Base URL
Client ID
Client Secret
Audit Client ID
Audit Client Secret

Related content

Links established from declared identifiers and solution manifests.

Source provenance

GitHub

Displayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.

Source identifier
CheckPointEmailSecConnector
Additional source files 2Solutions/Checkpoint Email Security/Data Connectors/CheckPointEmailSecurity_CCF/CheckPointEmailSecurity_ConnectorDefinition.jsonsource ↗Solutions/Checkpoint Email Security/Data/Solution_CheckPointEmailSecurity.jsonsolution-membership ↗
GSTEP / CATALOG TRACKING

Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 05:49 UTC

GSTEP sync dates, separate from the source content’s publication dates.