Enter Password



aiFWall Logo aiFObserve

Distributed, Contextual Visibility & Governance for Enterprise AI Traffic. No Agents, No APIs, No

Check Point Capture Guide For Unified aiFObserve

Best Capture Source

Use Check Point Log Exporter from the Management Server or Log Server. JSON, CEF, LEEF, syslog, and key-value text are supported by the converter, but JSON or clear key-value exports normally preserve the most useful fields.

Basic Logging

For rules allowing outbound SaaS and AI traffic:

  1. Enable logging in the Access Control policy.
  2. Use Detailed Log or Extended Log for application-aware rules.
  3. Use Per connection when you need constituent connections.
  4. Keep session logs enabled when you want user activity grouped by application or site.
  5. Export logs with Log Exporter.

Minimum fields to export:

Extended Logging

The converter groups related records by hll_key and then loguid so update chains can become one stronger session row.

User And App Identity

Best identity signals:

Use HTTPS Inspection where permitted to avoid generic HTTPS-only application labels.

AI Provider And Location Evidence

Keep destination address, country, application/site, URL, category, and HTTPS inspection fields. These help the compliance builder show AI provider usage and data boundary evidence.

Sources Used By The Original Firewall Guide