> Source: [sk182394](https://support.checkpoint.com/results/sk/sk182394)

# sk182394 - Cloud Log Analytics & Logging - Ingestion / Retention Solution

| Property | Value |
|----------|-------|
| Solution ID | sk182394 |
| Date Created | 2024-06-13 |
| Last Modified | 2026-07-27 |
| Technical Level | General |
| Products | SD-WAN, Endpoint Security, Events & AIOps, XDR |
| Versions | Cloud, Cloud, Cloud, Cloud |

## Solution

**Table of Contents**

* Overview
* Ingestion Packages use and explanation
* Managing Log Consumption
* Log Optimization
* Log Sharing - SmartConsole
* Notification and Capping Process
* Examples
* Frequently Asked Questions

<!-- -->

Overview {#Overview}
--------------------

Infinity Data Management (under Events) enables customers to access all events and logging data in a central cloud repository for easy analysis, monitoring, and reporting. It is an integral part of any SaaS-based solution, enabling collaborative security with Check Point XDR/XPR, advanced AI services, and data sharing across products.  

The new offering provides better visibility and optimization of data uploaded to the cloud.  

Most Check Point cloud solutions include default ingestion and retention quotas per offering.  

Entitled daily log ingestion is mentioned in the product catalog and summarized below:  

<br />

**Entitlement per product**   

|---------------|----------------|-------------------------------|-------------------------------------------------------------------------------------------------------------|
| **Product**   | **Asset Type** | **Ingestion Entitled GB/Day** | **Notes**                                                                                                   |
| Endpoint      | Seats          | 0.01 GB/day                   | All packages, only Endpoint logs (Threat Hunting logs are not enforced) **Reduced in Jan-2026**, see below. |
| XDR per user  | Seats          | 0.1 GB/day                    | *CP-INFINITY-XPR* **Reduced in Aug-2026,** see below.                                                       |
| XDR per GB    | GB             | 1 GB/day                      | *CP-INFINITY-XPR-1GB*                                                                                       |
| Smart-1 Cloud | Gateway        | 1GB/day or 3GB/day            | Based on contract type                                                                                      |
| IoT           | Gateway        | 0.05 GB/day                   |                                                                                                             |
| SD-WAN        | Gateway        | 7.5 GB/day or 10 GB/day       | Based on contract type. SMB or other Security Gateway                                                       |

<br />

**Important notes / changes:**   

* **January 2026 Change** : Endpoint entitlement was reduced from 0.2 GB/day to 0.01 GB/day following the removal of Threat Hunting from Endpoint capacity. There is no functional change - all Threat Hunting logs remain visible under the Endpoint service in the portal, but they are no longer included in Endpoint ingestion.
* Between**May 18--28, 2026** : S1C packages were updated to include additional bundled services (AIOps, Policy, Playblocks, etc.). This update caused an issue with ingestion capacity, leading to**duplicated quota values** and an inflated ingestion quota display in the portal.
* **3-August-2026: XDR entitlement was reduced** from 0.2 GB/day to 0.1 GB/day following the removal of Threat Hunting from Endpoint capacity. If required capacity is from on-prem to cloud, please use the XDR per GB package.

<br />

If additional daily log ingestion is required, two packages are available:  

* Infinity **Events** Package: Adds extra daily log ingestion for all cloud services.
* Infinity **XDR**: Adds ingestion plus cross-product detection and prevention

<br />

A dedicated dashboard is available under Infinity Events \> Dashboards \> Log Ingestion.  

<br />

*** ** * ** ***

Packages use and explanation {#Ingestion Packages use and explanation}
----------------------------------------------------------------------

### Events

Packages for exceeding customers (non-XDR):

|-------------------------------|---------------------------------------------------------------------------------------------------------------------------------------------------|------------------------|----------------------|
| **SKU**                       | **Description**                                                                                                                                   | **Ingestion (GB/day)** | **Retention (Days)** |
| CPSM-EVENTS-ESSENTIAL-RET3M   | 10 GB/day ingestion providing up to \~1TB of storage, suitable for businesses with low data volumes.                                              | 10                     | 90                   |
| CPSM-EVENTS-PREMIUM-RET3M     | 50 GB/day ingestion providing up to \~5TB storage, suitable for businesses with moderate data volumes.                                            | 50                     | 90                   |
| CPSM-EVENTS-PERFORMANCE-RET3M | 500 GB/day ingestion providing up to \~50TB of storage, suitable for businesses with critical data processing requirements or large data volumes. | 500                    | 90                   |

**Basic offering includes 90-day retention.**

### XDR

For XDR customers exceeding entitlement:

|---------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------|------------------------|----------------------|
| **SKU**             | **Description**                                                                                                                                                | **Ingestion (GB/day)** | **Retention (Days)** |
| CP-INFINITY-XPR-1GB | 1 GB/day ingestion, based on additional capacity required to support XDR use. This SKU provides XDR analytics capabilities in addition to daily log ingestion. | 1                      | 90                   |

### Retention Packages:

To extend retention beyond 90 days:  

|------------------------|-------------------------------------------------------------------------|------------------------|----------------------|
| **SKU**                | **Description**                                                         | **Ingestion (GB/day)** | **Retention (Days)** |
| CPSM-EVENTS-EXT-RET6M  | Cloud Events Retention Extension of 10GB to 6 months. Priced per year.  | 0                      | 180                  |
| CPSM-EVENTS-EXT-RET12M | Cloud Events Retention Extension of 10GB to 12 months. Priced per year. | 0                      | 365                  |
| CPSM-EVENTS-EXT-RET13M | Cloud Events Retention Extension of 10GB to 13 months. Priced per year. | 0                      | 390                  |

<br />

Important: Use Events extension SKU regardless of SaaS product. Multiple units are required for higher ingestion.  

<br />

#### **Retention Behavior and Upgrade Rules (New)**

* Retention applies to all tenant data.
* Maximum retention wins: If any SKU has \>90 days retention, all data aligns to the longest retention.
* Effective date: Retention changes apply from the day the new contract is activated.
  * Only new data ingested from that day forward uses updated retention.
  * Older data retains previous retention.
* Example: Jan 2025 ? Retention was 90 days.
  * 05 Mar 2025 ? 6-month retention added.
  * Data from 06 Mar onward retained for 6 months; older data stays at 90 days.

*** ** * ** ***

Managing Log Consumption
------------------------

* Access Infinity Events \> Dashboards \> Log Ingestion.
* View:
  * Average daily ingestion per month
  * Daily ingestion trends

Zoom for specific time periods. See Infinity Events Administration Guide.  

*** ** * ** ***

Log Optimization
----------------

* **Quantum customers:** Use Session logs instead of Connection logs to reduce consumption by up to 70% (see sk181096).
* **Endpoint:** See sk183109 for optimization tips.

*** ** * ** ***

Log Sharing -- SmartConsole
---------------------------

* Requires a valid contract covering daily ingestion capacity.
* Evaluation option: Events Evaluation (10GB/day for 30 days).
* Without a contract, enabling Log Sharing triggers an error:
  * "A contract is required in order to share logs to the cloud. See sk182394."

![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk182394/contract202501191437081.png)  

To **estimate the ingestion throughput** created by your environment (from on-prem to cloud), you may use the script in [sk181549](https://support.checkpoint.com/results/sk/sk181549)for an existing setup.   

### Understanding Log Size Differences in Cloud vs. On-Prem

Log Size vs. Disk Size: The size of a log during ingestion (when it's processed and indexed) differs from its disk size. On-disk size is typically smaller due to compression, but cloud logging costs are usually calculated based on the uncompressed size.  

On-Prem Logs: While you can estimate the disk size of log files on-prem, it's important to remember that logs are also indexed to enable fast searches and dashboards. These index files are typically about the same size as the original logs, effectively doubling the total disk usage.  

Cloud Logging Technologies: Cloud services often use different technologies and formats - typically more textual than binary - to support advanced analysis features.   

*** ** * ** ***

Notification and Capping Process {#Notification and Capping Process}
--------------------------------------------------------------------

* Notifications are daily; quota is daily.
* Alerts are sent at the end of the day UTC if the quota is exceeded.
* Status thresholds:

|-----------------------|------------|--------------------|-----------------------------|
| **Daily Ingestion %** | **Status** | **Email Interval** | **Impact**                  |
| \<80%                 | Normal     | None               | -                           |
| 80--100%              | Warning    | Every 5 days       | Warning                     |
| \>100%                | Exceeding  | Daily              | Warning before capping      |
| \>100% + grace        | Capping    | Daily              | Part of the logs are capped |

<br />

**Grace Period:**   
A default 48?hour grace period begins once ingestion exceeds 100% of the entitlement + grace. Capping occurs only after this period.  

**Logs After Capping:**   
Once capping is active, logs above 100% + grace are not uploaded to the cloud for that UTC day.  

<br />

**Additional Clarification:**   
A default grace is added above 100% of the entitlement.  
However, the recommended action is to increase the quota to avoid reaching the capping threshold.  

If a tenant reaches capping and remains in capping status for 48 hours consecutively, then:  

Data above 100% + grace is not ingested, meaning it will not be uploaded to the cloud.  
This drop happens only if the tenant stays in capping for 48 consecutive hours.  
Logs resume ingestion the following day, once ingestion falls back within the allowed thresholds.  

<br />

*** ** * ** ***

Examples {#Examples}
--------------------

**Example #1:**  
A customer is planning to ingest 60 GB/day of data from on-premise to cloud, and would like to purchase a retention extension to 1 year (due to compliance):  

|-----------------------------|------------------------|------------------|---------------------|
| **SKU**                     | **Ingestion (GB/day)** | **QTY Required** | **Total Ingestion** |
| CPSM-EVENTS-PREMIUM-RET3M   | 50                     | 1                | 50                  |
| CPSM-EVENTS-ESSENTIAL-RET3M | 10                     | 1                | 10                  |
| CPSM-EVENTS-EXT-RET12M      | 10                     | 6                | 60                  |

<br />

Explanation:  
To reach 60 GB per day ingestion, the quote should include a combination of 50+10 GB/day SKUs.  
Then, to extend the 90-day retention (included) to 365 days (1 year), an additional extension SKU (CPSM-EVENTS-EXT-RET12M) must be added.  
Since the extension SKU is per 10 GB/day, 6 units of this SKU need to be added to reach a 60 GB/day extension.

**Example #2:**  
The customer has Endpoint licenses with 1000 seats purchased, providing 10 MB per seat.  
Requires retention of more than 90 days, to a full year.  

|------------------------|------------------------|-----------|---------------------|
| **SKU**                | **Ingestion (GB/day)** | **Seats** | **Total Ingestion** |
| CPSM-EVENTS-EXT-RET12M | 0.01                   | 1000      | 10                  |

<br />

Explanation:  
1000 seats x 0.01 GB/day per seat = 10 GB  
Retention SKU is 90 days.  

**Example #3:** The customer has 1000 users.  
He purchased Harmony Elite with 1000 seats each.  
Harmony Elite is a SKU for Harmony Endpoint with Infinity XDR/XPR for Harmony Endpoint only.

|----------------------|----------------------|-------|-------------------|
| Product              | Entitlement per seat | Units | Total entitlement |
| Endpoint Elite (EDR) | 0.01 GB/day          | 1000  | 10 GB/day         |

<br />

<br />

*** ** * ** ***

<br />

Frequently Asked Questions (FAQs) {#FAQ}
----------------------------------------

******Q: How do I know which ingestion package to get?******  
> When XDR/XPR is used, use the extension package named "Infinity XDR/XPR - Per daily data consumption (GB)". When XDR/XPR is not used, use the Infinity Events log packages.  
>
> The packages offered are based on ingestion per day limit with retention duration.  
> For example, the Essential package is limited to 10GB/day ingestion with a 3-month retention period.   
>
> Purchasing more ingestion capacity can increase ingestion throughput but not retention length. Purchasing a retention extension package can increase the retention duration from 3 months to a year.  
>
> To estimate the ingestion throughput created by your environment, you may use the script in [sk181549](https://support.checkpoint.com/results/sk/sk181549 " sk181549") for an existing setup.

**Q: How can I increase retention to longer than 3 months?**  
> Each package includes a 3 months retention. In order to increase retention to 1 year, you can purchase a "Retention Extension" SKU.  
>
> Each Retention Extension SKU provides an extension of 10GB/day. Higher ingestion would require purchasing multiple SKUs to match the total ingestion required.  
>
> For example, if you have purchased the Efficient ingestion SKU, you have 50 Gbps/day ingestion for 3 months. To expand that to 1 year, you should purchase   
> 5 x Retention Extension SKUs (10 Gbps/day) = 50 Gbps extension retention.  
>
> **Maximum retention possible is 1 year.**   

**Q: What happens if my environment exceeds my purchased ingestion limit?**  
> The ingestion limit relates to the amount of logs ingested into the cloud per day (usually defined in GB per day). You can view your daily ingestion needs in the dedicated dashboard. If your ingestion is above 80%, either purchase additional storage packages (to increase ingestion quota) or reduce your logging throughput. The Infinity Portal will provide warnings when approaching the ingestion limit and will eventually throttle ingested logs.

**Q: What can I do if additional time is required for PoC or for more expiration time?**  
> There is an EVAL of ingestion that can be requested (SKU: CPSM-EVENTS-ESSENTIAL-RET3M-EVAL), each EVAL gives10GB/day.  
> In order to add it, issue internal order or ask Check Point representative for such contract as it required approval.  
>
> How many contracts are required?   
> If 50 GB/day are required in addition than the the QTY needs to be 10 GB/day x 5 units = 50 GB/day.  
>
> Make sure to add justification, with ETA for resolving the issue.

**Q: How do I free up memory or delete old logs?**  
> Log storage is based on a daily ingestion quota, which automatically resets every day. You cannot manually free up capacity by deleting old logs.

**Q: Why do I see changes in the ingestion during October - November 2025?**  
> We identified an ingestion reporting miscalculation during September - October, which caused lower ingestion values to appear in dashboards for several days. The issue was fixed around October 27, and values have since returned to normal.  
> **Important:**There is no impact on customers - all logs were ingested correctly.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
