> Source: [sk162613](https://support.checkpoint.com/results/sk/sk162613)

# sk162613 - Configure Sumo Logic as a Log system for CloudGuard 

| Property | Value |
|----------|-------|
| Solution ID | sk162613 |
| Date Created | 2019-10-02 |
| Last Modified | 2023-03-05 |
| Technical Level | General |
| Products | Cloud Firewall |
| Versions | R82.10, R81.20, R82 |

## Solution

This note describes how to configure CloudGuard to send compliance findings to Sumo Logic. This involves the configuration of an HTTP Event Collector on your Sumo Logic instance, and the configuration of a Compliance Notification Policy on CloudGuard.

Configure an HTTP Endpoint on Sumo Logic
----------------------------------------

You must have administrator credentials on Sumo Logic to configure an HTTP Endpoint.

1. Sign in to Sumo Logic (as admin).
2. Select **Set Up Streaming Data** in the Setup Wizard.  

   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk162613/SumoLogic-SetupWizard1910020628.png)
3. Click **All Other Sources** for the Data Type.  

   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk162613/SumoLogic-SetupWizard-DataType1910020630.png)
4. Select **HTTPS Source** for the Set up Collection.  

   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk162613/SumoLogic-SetupWizard-Setup-Collection1910020631.png)
5. Enter *Dome9-Collector* for the Source Category, and then click **Continue**.
6. Copy the HTTP Source URL, and then click **Continue** .  

   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk162613/SumoLogic-SetupWizard-HTTP-Source1910020635.png)

Configure a CloudGuard Compliance Notification Policy
-----------------------------------------------------

1. Sign in to the CloudGuard Web app (https://secure.dome9.com), and navigate to the **Notification** page in the **Compliance \& Governance** menu.
2. Click **ADD NOTIFICATION**.
3. Enter a name for the notification (for example, *SumoLogic*), and a description.
4. Select *Send to HTTP Endpoint* in the Immediate Notification section.
5. Enter the HTTP Source URL, from the previous section, in the Endpoint URL field. ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk162613/2020-06-21 15_03_50-Dome9 _ Manage Notifications202006211508301.png)  
   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk162613/2020-06-21 15_03_50-Dome9 _ Manage Notifications202006220833451.png)
6. Leave the Authentication Type as *No Authentication* and the format as *Sumo Logic.*
7. Click **SAVE**.

This notification policy will forward findings to the SumoLogic HTTP collector, configured above.

Configure a CloudGuard Compliance Policy
----------------------------------------

This step configures a CloudGuard continuous compliance policy, for a selected cloud account and Dome9 Ruleset, to send any findings to the SumoLogic collector.

1. In the Dome9 Web Application, navigate to **Policies** in the **Compliance \& Governance** menu.
2. Click **ADD POLICY**.
3. Select the cloud platform and account on which the Ruleset will be applied.
4. Select the Rulesets to be applied to the selected accounts.
5. Select the SumoLogic notification policy, and then click **SAVE** .  
   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk162613/Dome9- Manage-Policy-Notification-Sumo1910020659.png)

The rulesets in the policy will be applied to the selected accounts continuously (approximately every hour). Any findings will be forwarded to the SumoLogic Collector.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
