TEAM: Huntress Managed Security Information and Event Management (SIEM)
PRODUCT: SIEM Syslog
ENVIRONMENT: Barracuda CloudGen Firewall
SUMMARY: Configuration Guide for Barracuda CloudGen Firewalls
This page only covers the device-specific configuration, you'll still need to read Huntress Managed SIEM Syslog Guide to complete the Huntress Managed SIEM setup as well as opening a port in Microsoft Defender Firewall.
Vendor Information
|
Vendor |
Barracuda |
|---|---|
|
Supported Model Name/Number |
CloudGen Firewall |
|
Supported Software Version(s) |
8.3, 9.0 |
|
Collection Method |
Syslog |
|
Query Syntax: event.provider |
Syslog-BarracudaCloudGen |
|
Billable Sources Calculation |
1 Billable Source Per Inbound Source IP |
|
Vendor Links |
Please note that Huntress provides third party vendor instructions as a best effort to expedite onboarding. Vendor documentation and versions frequently change and so it may be necessary to find the appropriate documentation for syslog logging for your version of the vendor software or service.
Please note the link in the Vendor Links above to the latest documentation at the time of this writing.
Device Configuration Checklist
Enable the Syslog Service
-
Go to CONFIGURATION > Full Configuration > Box > Infrastructure Services > Syslog Streaming
-
Click Lock
-
Set Enable Syslog Streaming to yes
-
Click Send Changes and Activate
Note: Huntress SIEM does not support TLS or receiving encrypted data from syslog sources. If you setup your source with TLS Huntress will not be able to ingest data from that source.
Configure Logdata Filters
-
Go to CONFIGURATION > Full Configuration > Box > Infrastructure Services > Syslog Streaming
-
In the left menu, select Logdata Filters
-
Expand the Configuration Mode menu and select Switch to Advanced View
-
Click Lock
-
Click the + icon to add a new entry
-
Enter a descriptive name in the Filters dialog and click OK.
-
In the Affected Box Logdata section, choose the box logs sent via syslog
-
Click the + next to Data Selection to add an entry
-
Enter a descriptive name for the group and click OK. The Data Selection window opens.
-
Choose the following items from the Data Selection window: Auth-All, Config-All, Control-All, Event-All, Firewall-Activity-Only, Firewall-Threat-Only, Network-All, Settings-All, SSH-All, System-All, Watchdog-All
-
Choose the following items from Message Types: Panic, Security, Fatal, Error, Warning, Notice
-
Click OK
-
-
Click Send Changes and Activate
Configure Logstream Destination
-
Go to CONFIGURATION > Full Configuration > Box > Infrastructure Services > Syslog Streaming
-
In the left menu, select Logstream Destinations
-
Expand the Configuration Mode menu and select Switch to Advanced View
-
Click Lock
-
Click the + icon to add a new entry
-
Enter a descriptive name for the destination (such as Huntress Collector) and click OK. The Destinations window opens.
-
Select the Logstream Destination
-
Select Explicit IP
-
Set the Destination IP Address to the Internal IP of the Huntress agent configured to receive syslog
-
-
Set the Destination Port to 514
-
Set the Transmission Mode to UDP
-
Click OK
-
Click Send Changes and Activate
Configure Logdata Streams
-
Go to CONFIGURATION > Full Configuration > Box > Infrastructure Services > Syslog Streaming
-
In the left menu, select Logdata Streams
-
Expand the Configuration Mode menu and select Switch to Advanced View
-
Click Lock
-
Click the + icon to add a new entry
-
Enter a descriptive name for the new configuration (such as Huntress Log Stream) and click OK
-
Configure the following settings
-
Active Streams to yes
-
Log Destinations to the destination created above
-
Log Filters to the filter created above
-
-
Click Send Changes and Activate
Example Log Messages
Firewall Traffic
<14>Feb 6 19:14:59 hostname hostname/box_Firewall_Activity: Info hostname Allow: FWD|TCP|p1|10.36.87.167|63102|e4:54:e8:81:49:42|142.250.187.227|80|http|p2|BOX-LAN-2-INTERNET|0|195.224.222.166|142.250.187.227|0|1|0|0|0|0||||||