TEAM: Huntress Managed Security Information and Event Management (SIEM)
PRODUCT: Firewall Syslog
ENVIRONMENT: Barracuda CloudGen Firewall
SUMMARY: Configuration Guide for Barracuda CloudGen Firewalls
Vendor Information
Vendor |
Barracuda |
---|---|
Supported Model Name/Number |
CloudGen Firewall |
Supported Software Version(s) |
8.3, 9.0 |
Collection Method |
Syslog |
Provider Name |
Syslog-BarracudaCloudGen |
Additional Information |
Device Configuration Checklist
Enable the Syslog Service
-
Go to CONFIGURATION > Full Configuration > Box > Infrastructure Services > Syslog Streaming
-
Click Lock
-
Set Enable Syslog Streaming to yes
-
Click Send Changes and Activate
Configure Logdata Filters
-
Go to CONFIGURATION > Full Configuration > Box > Infrastructure Services > Syslog Streaming
-
In the left menu, select Logdata Filters
-
Expand the Configuration Mode menu and select Switch to Advanced View
-
Click Lock
-
Click the + icon to add a new entry
-
Enter a descriptive name in the Filters dialog and click OK.
-
In the Affected Box Logdata section, choose the box logs sent via syslog
-
Click the + next to Data Selection to add an entry
-
Enter a descriptive name for the group and click OK. The Data Selection window opens.
-
Choose the following items from the Data Selection window: Auth-All, Config-All, Control-All, Event-All, Firewall-Activity-Only, Firewall-Threat-Only, Network-All, Settings-All, SSH-All, System-All, Watchdog-All
-
Choose the following items from Message Types: Panic, Security, Fatal, Error, Warning, Notice
-
Click OK
-
-
Click Send Changes and Activate
Configure Logstream Destination
-
Go to CONFIGURATION > Full Configuration > Box > Infrastructure Services > Syslog Streaming
-
In the left menu, select Logstream Destinations
-
Expand the Configuration Mode menu and select Switch to Advanced View
-
Click Lock
-
Click the + icon to add a new entry
-
Enter a descriptive name for the destination (such as Huntress Collector) and click OK. The Destinations window opens.
-
Select the Logstream Destination
-
Select Explicit IP
-
Set the Destination IP Address to the IP of the Huntress agent configured to receive syslog
-
-
Set the Destination Port to 514
-
Set the Transmission Mode to UDP
-
Click OK
-
Click Send Changes and Activate
Configure Logdata Streams
-
Go to CONFIGURATION > Full Configuration > Box > Infrastructure Services > Syslog Streaming
-
In the left menu, select Logdata Streams
-
Expand the Configuration Mode menu and select Switch to Advanced View
-
Click Lock
-
Click the + icon to add a new entry
-
Enter a descriptive name for the new configuration (such as Huntress Log Stream) and click OK
-
Configure the following settings
-
Active Streams to yes
-
Log Destinations to the destination created above
-
Log Filters to the filter created above
-
-
Click Send Changes and Activate
Example Log Messages
Firewall Traffic
<14>Feb 6 19:14:59 hostname hostname/box_Firewall_Activity: Info hostname Allow: FWD|TCP|p1|10.36.87.167|63102|e4:54:e8:81:49:42|142.250.187.227|80|http|p2|BOX-LAN-2-INTERNET|0|195.224.222.166|142.250.187.227|0|1|0|0|0|0||||||