Check Point Harmony Email & Collaboration

The Dropzone AI platform integrates with Check Point Harmony Email & Collaboration APIs. This document describes how to set up OAuth credentials in the Check Point Infinity Portal and install them into the Dropzone platform.

The integration automatically ingests the following email security alert types from Check Point Harmony:

  • phishing - Phishing email alerts

  • malware - Malware email alerts

  • suspicious_phishing - Suspicious phishing email alerts

  • suspicious_malware - Suspicious malware email alerts

  • anomaly - Admin-blacklisted emails and other anomalies

Create Oath credentials

Check Point Harmony requires an Account API Key to enable. To create an Account API Key, do the following:

  • In your Check Point Infinity Portal, navigate to ⚙️ > API Keys

  • Navigate to New > New account API key

Click "New Account API Key"
  • Under "Service," select Email & Collaboration

  • In the Expiration field, select an expiration date and time for the API Key

  • In the Description field, enter a memorable description for the API Key, such as "Dropzone AI"

  • Click "Create"

Create the API Key
  • Copy the Client ID, Secret Key, and Authentication URL shown for use later in the Dropzone UI where they are called "Client ID," "Secret Key," and "Authentication URL (API Endpoint)" respectively

  • Click "Close"

Copy the API Key details

For additional information, see the Check Point Infinity Portal API Keys Documentation.

Enable Check Point Harmony

The Alert source integration allows Dropzone AI to pull alerts from Check Point Harmony Email & Collaboration for investigation.

You'll need the following information:

Dropzone Field
Source

Client ID

The "Client ID" value you copied earlier

Secret Key

The "Secret Key" value you copied earlier

Authentication URL (API Endpoint)

The "Authentication URL" value you copied earlier

To enable the Alert Source integration, do the following:

  • Navigate to your Dropzone AI tenant home page e.g. https://mycompany.dropzone.app

  • In the bottom left hand corner, navigate to Settings > Integrations

Integrations Dropdown
  • Click "Available"

Click Available
  • In the Search bar, search Check Point, then click "Configure"

The Check Point Tile
  • Input the Client ID, Secret Key, and Authentication URL

The Check Point Harmony Alert Source Configuration (pt 1)
  • Under "Enabled Severities," select which severity levels to ingest from Check Point Harmony

  • Under "Enabled States," select which event states to ingest from Check Point Harmony

If all severities or all states are disabled, no alerts will be fetched.

The Check Point Harmony Alert Source Configuration (pt 2)
  • Input your desired poll interval and lookback

The Check Point Harmony Alert Source Configuration (pt 3)
  • Click "Test & Save" to finish

You should begin ingesting alerts immediately.

This integration supports backfilling historical alerts via the AlertBackfill system. Backfills are processed in 1-hour chunks. See the Alert Sources overview for more information on backfilling.

If you have any errors engage your Dropzone AI support representative.

Last updated

Was this helpful?