> Source: [sk177503](https://support.checkpoint.com/results/sk/sk177503)

# sk177503 - Log4j detection in Compliance blade

| Property | Value |
|----------|-------|
| Solution ID | sk177503 |
| Date Created | 2022-01-20 |
| Last Modified | 2022-12-15 |
| Technical Level | General |
| Products | Endpoint Security |
| Versions | Cloud, E89.X, E88.X |
| OS | Windows |

## Solution

**What is log4j detection ?**   

As of Endpoint Clients version E86.30, Compliance blade provides scan and remediation for vulnerable log4j files. The vulnerable machines are reported in the compliance reporting tab if remediation is impossible. Every 24 hours the compliance blade scans for vulnerable log4j files and reports its findings in management reporting.  

**How to enable Log4j detection?**

1. In the Compliance rule, create a check object that checks `HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\CheckPoint\Endpoint Security\Compliance\Log4jScan value = 1`  

   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk177503/Test202201201102222.png)   

   The check's action and message are defined by the administrator.  

   **Note** - On SmartEndpoint, to access this window, you must add a new rule under **Compliance** \> **Prohibited - Malicious and vulnerable applications.**
2. Install policy. Log4j detection now works on the effected machines.

**When Log4j Scan will run ?**   

Log4j scan will run every 24 hours and on idle time.  

Compliance takes windows update idle from "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WindowsUpdate\\UX\\Settings"  

If the scan didnt run for 2 days, the scan will run regardless of the time   
**How to disable Log4j detection?** Remove the check under **Compliance rule base -\> Install policy** to disable detection.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
