> Source: [sk181096](https://support.checkpoint.com/results/sk/sk181096)

# sk181096 -  How to Optimize Quantum Cloud Logs

| Property | Value |
|----------|-------|
| Solution ID | sk181096 |
| Date Created | 2023-06-15 |
| Last Modified | 2025-05-22 |
| Technical Level | General |
| Products | Smart-1 Cloud |
| Versions | Cloud |
| OS | Gaia |

## Solution

**Background**

For each policy rule, you can configure either per session logging or per connection (or both).

|--------------------|-------------------------------------------------------------------|-----------------------------------------------------------------------------------------------------------------------------|
| Item               | Connection Logs                                                   | Session Logs                                                                                                                |
| Definition         | Per individual connection that the Security Gateway is inspecting | Collection of multiple connections with the same parameters, such as source, destination, application, port, protocol, user |
| Duration of update | Per connection                                                    | Session continues for three hours                                                                                           |
| Log volume         | Connection logs are approximately eight times more than session logs                                                                                                                           ||

<br />

Infinity Events has the ability to view rules that generate the most logs. This data is extremely useful to optimize or minimize the log rate.

Follow these procedures to enhance Smart-1 Cloud logs:

1. Open the **Infinity Events** service:

   1. Log in to Check Point Infinity Portal with your Smart-1 Cloud account.

   2. In the top left corner, click the **Menu** button.

   3. In the **Infinity** pillar, click **Events**.

      ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk181096/a202412290817421.png)

      **Note** : If you are using **Infinity Events** for the first time, select the checkbox "**I Accept the Terms of Service and the Privacy Policy** " and click **Get Started**.

      ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk181096/bbbbb202402141105522.png)
   4. In the left panel, in the **Security Events** section, click **Logs**.

      This page shows statistics for all the logs recorded in the system.

      ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk181096/b202412290818422.png)
2. To create a helpful filter view, click the Time Filter and select the applicable filter.

   For example, select **This Week**.

   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk181096/c202412290821003.png)

   You can see the total number of logs for the selected time filter in the widget **Statistics**.

   Example:

   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk181096/d202412290822324.png)
3. In the facets **Product Family** and **Cloud Services**, select the applicable items.

   **Note** : If **Product Family** has more than one product, then select **Quantum** , and for **Cloud Service** , select **Quantum Smart-1 Cloud.**

   Example:

   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/NEW_SK_NOID1686204833855/6202306080929336.png)
4. Configure the columns to show the required data.

   To add or change the columns:
   1. Right-click one of the columns \> click **Columns Profile Editor**.

   2. Select the columns.

      ![](https://sc1.checkpoint.com/sc/SolutionsStatics/NEW_SK_NOID1686204833855/7202306080930227.jpg)

      **TIP:** Select **Origin** , **Rule Name** , and **Rule Number** as new columns.

      ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk181096/111202307230909571.png)
   3. Statistics in the **Origin** column shows the top logs contributor (in most cases, examine it first):

      ![](https://sc1.checkpoint.com/sc/SolutionsStatics/NEW_SK_NOID1686204833855/9202306080932389.png)

      Show the **Source** and **Destination** columns.

      ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk181096/10202306080940572.png)

      **Note:** Unlike the other statistics (**Rule Number** and **Rule Name**), it is not possible to filter them (the relevant checkboxes are disabled).
5. Showing logs from internal DNS and internal server traffic:

   In cases where internal traffic or internal DNS adds a very high number of logs and you want to decrease the internal traffic logging, create a rule that accepts or block this traffic with **Track** set to **None** or **Log per Session**.

   **Important:** Reducing the number of logs means the visibility of events is reduced, and you must do it after reviewing all the security aspects.
   * Example rule with "Track = None"

     Does not create a log for this connection.

     ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk181096/dns3202312280952102.png)
   * Example rule with "Track = Log per Session"

     Creates one log for all the connections in the same session.

     ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk181096/12202306080947234.png)

     ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk181096/13202306080947345.jpg)

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
