

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Checkpoint caching
Hi, I have one checkpoint Firewall which caches most of the time. I have made the batching to 300:1 and increased the java heap to 1 Gb but still same. what else can I do to decrease the caching on connector

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
What is EPS?


- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
sent to manager EPS is 1992.5


- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Total sent to manager EPS is 7833.1 and for checkpoint it is 2019.6


- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content


- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
I am using a Check Point OPSEC NG connector for this and are you talking about CPU or ESM transport multithreading ? and should there be a agent.default.properties file because its not there?

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Hi Samal ,
Please add below parameter in agent.propertiy
http.transport.threadcount=16
http.transport.multithreaded=true
eventcache.scanforsize=false
http.transport.queuesize=600
agents[0].checkpoint.parser.multithreading.enabled=true

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
What is ESM Manager version? It may be not able to ingest such high EPS. Though Check Point feed is well compressed usually (btw, check that you enabled field based aggregation) and should not be a problem.


- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
ESM 6.8. What do you suggest the field based aggregation value to be ?


- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
I added all of these values but still its caching..

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
For Check Point I would suggest the following field based aggregation settings:
Time Interval: 15s
Event Threshold: 1000
Field Names: name, message, transportProtocol, destinationAddress, destinationPort, sourceAddress, deviceAddress
Fields to Sum: bytesIn, bytesOut
Preserve Common Fields: Yes
Important:
Enables aggregation (in secs): Disabled
This is a tricky part since the last setting is not global and it does not affect field based aggregation.

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
What is RAM allocation for the ESM Manager? Allocate at least 32Gb.