> Source: [sk182647](https://support.checkpoint.com/results/sk/sk182647)

# sk182647 - Events & AIOps

| Property | Value |
|----------|-------|
| Solution ID | sk182647 |
| Date Created | 2024-09-17 |
| Last Modified | 2026-09-06 |
| Technical Level | General |
| Products | Events & AIOps |
| Versions | Cloud |

## Solution

### Table of Contents

1. Onboarding Process
2. Known Limitations
3. Non-Formal Onboarding (for unsupported versions)
4. Troubleshooting

### Onboarding Process {#Onboarding Process}

#### Prerequisites \& Onboarding Instructions

Follow the steps outlined in the [Events \& AIOps Administration Guide](https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Events-Admin-Guide/cshelp.html?contextId=AIOPS001) for the standard onboarding process.

### Known Limitations {#Known Limitations}

#### General Issues

* Connectivity problems may occur if Security Gateways or Clusters are misconfigured. After resolving such issues, click **Reactivate** to restore monitoring.
* Multitenant / multisession environments are not supported by default.
* For each Management, only the associated VSNext Members can be viewed.
* SD-WAN assets monitoring:
  * SD-WAN monitoring in AIOps is currently not supported for Smart-1 Cloud tenants.
  <!-- -->

  * Alert evaluation delay: SD-WAN asset alerts are evaluated every 5 minutes. As a result, an alert may take up to 5 minutes to appear or clear after its condition changes.

#### Product Limitations

|-----------------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| ID                    | Description                                                                                                                                                                                 |
| AIOPS-450             | Automatic onboarding for Security Gateways managed with SmartProvisioning (LSM) is not supported                                                                                            |
| AIOPS-2509            | Adding and monitoring Spark devices is currently not supported.                                                                                                                             |
| AIOPS-1846 AIOPS-1844 | Due to the presence of unmonitored assets in AIOps that trigger alerts via SMC, some data inconsistencies may occur.                                                                        |
| AIOPS-1728            | Alerts Table is limited to 150 alerts.                                                                                                                                                      |
| AIOPS-240             | Cluster Failover may cause data delays.                                                                                                                                                     |
| AIOPS-1632            | On VSX Cluster, member IPs may not be displayed.                                                                                                                                            |
| AIOPS-1767            | Automatic onboarding for Multi-Domain Security Management (MDS) is not supported. The solution installed only on the Security Gateways connected but not on the Security Management Server. |
| AIOPS-2004            | In Smart-1 Cloud, only Security Gateway data is displayed.                                                                                                                                  |
| AIOPS-2735            | In rare scenarios, duplicated Management objects appear linked after machine rebuild.                                                                                                       |
| CPDIAG-4260           | Automatic onboarding for Scale Cloud Gateway is not supported                                                                                                                               |
| DP-15474              | AIOps supports a total of 400 onboarded Security Gateways per tenant                                                                                                                        |
| DP-15792              | AIOps is not supported when using Private Threat Cloud (PTC) environment                                                                                                                    |
| DP-15796              | Automatic onboarding for Maestro Hyperscale Orchestrator (MHO) is not formally supported. A workaround (**Non-formal onboarding**) is available as described below.                         |
| DP-16435              | Automatic onboarding for Log Server / Multi-domain Log Server is not formally supported.                                                                                                    |
| DP-16466              | During upgrade, some assets may not appear correctly in *Gateways \& Servers* section. The issue is resolved starting R82.20.                                                               |

### Non-Formal Onboarding (For Unsupported Versions) {#NonFormal Onboarding}

A non-formal onboarding method exists for older versions or unsupported assets.  

#### Prerequisites

* **Security Management / Multi-Domain Security Management Server**

R81.20: Install [Jumbo Hotfix Accumulator](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20/R81.20/Introduction.htm?tocpath=_____1), Take 101 or higher   
[Check Point R82 Release](https://support.checkpoint.com/results/sk/sk181127) and higher

* **Security Gateways / Traditional VSX / Clusters / Maestro Appliances**

R81.10: Install [Jumbo Hotfix Accumulator](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.10/R81.10/Introduction.htm), Take 113 or higher   
R81.20: Install [Jumbo Hotfix Accumulator](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20/R81.20/Introduction.htm?tocpath=_____1), Take 43 or higher   
[Check Point R82 Release](https://support.checkpoint.com/results/sk/sk181127) or higher

#### Non-Formal Onboarding Steps

1. Download the [AIOps.sh](https://support.checkpoint.com/results/download/134891) script file to your local computer.
2. Copy the script to any folder on the **Quantum Management Server**.
3. Connect via SSH and enter Expert mode.
4. Navigate to the folder with the script.
5. Run:   
   `chmod +x ./AIOps.sh `  
   **./AIOps.sh --region**` <region - e.g eu,us,in,aus> `

**Note** - For Multi-Domain / Domain Management Server setup, run with domain parameter:  
**./AIOps.sh --region** `<region- e.g eu,us,in,aus> `**--domain**` <CMA name> `  

After onboarding is complete, the Management Server will try to connect to Infinity AIOps. This may take a few minutes.  

### Troubleshooting {#Troubleshooting}

|------------------------------------------------------------------------|-----------------------------------------------------------------------------------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| **Error Message**                                                      | **Issue Description**                                                                               | **Root Cause**                                                                                                                                                                                                                                                                             | **Resolution**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| Connectivity issues                                                    | Data transmission from the user environment is blocked                                              | Outbound connections are not allowed                                                                                                                                                                                                                                                       | Ensure that outbound connections are allowed to the following IP addresses and URLs. See [Onboarding AIOps](https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Events-Admin-Guide/Content/Topics-Events-Admin-Guide/Onboarding-AIOps.htm?tocpath=AIOps%7COnboarding%20AIOps%20(Automatic%20Mode)%7C_____0#Onboarding_AIOps_(Automatic_Mode)) section in [AIOps Admin Guide](https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Events-Admin-Guide/Content/Topics-Events-Admin-Guide/Infinity_AIOps.htm?tocpath=AIOps%7CAIOps%20-%20Introduction%7C_____0#AIOps_-_Introduction) |
| SmartTask execution fails during policy installation                   | SmartTask execution fails                                                                           | SmartTask execution fails during policy installation, on AIOps trigger, because of inconsistency in the SmartTask or its associated repository script.                                                                                                                                     | Perform these steps on the Management Server CLI to resolve the issue: <br /> * mgmt_cli -r true delete repository-script name "installPolicyEvent" -f json * mgmt_cli -r true delete smart-task name "Send Install Policy Event - Aiops" -f json * /opt/CPotlpAgent/CPotlpagentCli.sh stop * /opt/CPotlpAgent/CPotlpagentCli.sh start                                                                                                                                                                                                                                                                                 |
| AIOps portal displays the message: "No available data since XXX hours" | Security Gateway is not sending data to AIOps                                                       | The CPOTELCOL process receives metrics from multiple agents and exports them externally (see [sk180522](https://support.checkpoint.com/results/sk/sk180522)). but cant export the CPView, triggering the "No data" error                                                                   | 1. Restart Skyline processes (per [sk179870](https://support.checkpoint.com/results/sk/sk179870) ): * **OpenTelemetry Collector (CPotelcol)** : 1. `/opt/CPotelcol/stop` 2. `/opt/CPotelcol/start` * **CPView Exporter** : 1. `/opt/CPviewExporter/stop` 2. `/opt/CPviewExporter/start` * **CPView API Service** : 1. `cpview -a off` 2. `cpview -a on` 2. If still unresolved, collect these diagnostic files and contact Check Point Support: * **CPinfo** : `cpinfo -d -D -z -o /var/log/$(hostname).cpinfo` * **Health Check Point (HCP)** : `hcp -r all --include-wts yes` * **Skyline** : `sklnctl collect_logs` |
| OS Gaia Proxy Configuration                                            | Metrics are not reaching Infinity Portal even though connectivity tests (telnet/curl_cli) succeed   | The OpenTelemetry Collector (otelcol) inherits the Gaia operating system proxy configuration. As a result, telemetry traffic may be routed through the configured proxy,This can create a misleading situation where connectivity appears to be working, but metrics are silently dropped. | Verify the configured no-proxy list: *cat /opt/CPotelcol/no_proxy* Verify the Gaia proxy environment variables: *env \| grep -i proxy* Add the telemetry target to the no-proxy list:*echo '\<prometheus-host\>' \> /opt/CPotelcol/no_proxy* Restart the OpenTelemetry Collector:*/opt/CPotelcol/CPotelcolCli.sh stop /opt/CPotelcol/CPotelcolCli.sh start* After the restart, verify that metrics are successfully reaching the destination                                                                                                                                                                           |
| VSX Environment - Verify VS0 Is Onboarded                              | In a VSX environment, gateways are not reporting metrics or appear disconnected in Infinity Portal. | In VSX deployments, VS0 must be onboarded to Infinity Portal before any other Virtual System (VS) can operate correctly.                                                                                                                                                                   | From an MDS environment: *./aiops --domain \<domain_name\>* From a Standalone Management Server: *./aiops* After onboarding completes, verify connectivity again: *cpnano -s* *cpnano-vs0 -s* *cpnano-vs1 -s* *cpnano-vs2 -s* Repeat for all active VS contexts.                                                                                                                                                                                                                                                                                                                                                       |

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
