Check Point Avanan

Connect Check Point Avanan to Radiant Security to forward email security alerts for AI triage.

Check Point Avanan is a cloud email and collaboration security platform that protects Microsoft 365, Google Workspace, and connected SaaS apps against phishing, business email compromise, malware, and account takeover. Connecting Check Point Avanan forwards email security alerts to Radiant Security via webhook. Radiant uses these alerts to surface user-targeted attacks during AI triage, correlating mailbox activity with identity, endpoint, and network signals already in the pipeline.

Prerequisites

Add the data connector in Radiant Security

  1. Log in to Radiant Security.

  2. From the navigation menu, select Settings > Data Connectors and click + Add Connector.

  3. Search for and select Checkpoint Avanan Webhook, then click Data Feeds.

  4. Under Select your data feeds, select Checkpoint Avanan webhook and click Credentials.

  5. In the Credential Name field, enter an identifiable name (e.g., Avanan webhook credentials).

  6. In the Connector tag field, enter any string. Radiant uses this value as salt when generating the authentication token for your connector.

  7. Click Add Connector.

  8. On the Data Connectors page, find the new connector and click View Details. Under Vendor Configuration, copy and save the Webhook URL. You will paste it into the Avanan Portal in the next section.

Configure Check Point Avanan to forward security events

  1. Log in to the Avanan Portal.

  2. Navigate to Security Settings > Security Engines.

  3. Under SIEM Integration, click Configure.

  4. Under Transport Method, select HTTP Collector.

  5. In the URL field, paste the Webhook URL you copied from Radiant Security.

  6. Under Log Format, select JSON.

  7. Click Save.

Verify ingestion

After Check Point Avanan begins forwarding, confirm alerts are reaching Radiant.

  1. In Radiant, navigate to Log Management.

  2. Filter by rs_connectorType:"avanan_webhook".

  3. Confirm recent alerts appear.

Allow several minutes for alerts to be parsed, indexed, and available for search.

Last updated

Was this helpful?