Title: Syslog - SonicWall SMA
TEAM: Huntress Managed Security Information and Event Management (SIEM)
PRODUCT: SIEM Syslog
ENVIRONMENT: SonicWall SMA
SUMMARY: Configuration Guide for SonicWall SMA Syslog Forwarding, covers Secure Mobile Access 1000 series (6200, 6210, 7200, 7210, 8200v).
Vendor Information
| Vendor | SonicWall |
| Supported Model Name/Number | SMA 1000 Series (6200, 6210, 7200, 7210, 8200v) |
| Supported Software Version(s) | 12.4.x |
| Collection Method | Syslog (RFC 5424) |
| Provider Name | Syslog-SonicWall-SMA |
| Vendor Reference Links | SonicWall SMA 1000 - Sending log files to a syslog server |
- Setup your Huntress agent(s) as a syslog collector on your desired port and protocol.
- If Defender Firewall or any software firewall is on the collector agent endpoint you'll need to open your desired port and protocol.
- Follow the instructions from SonicWall to setup your device(s) to send data to the Huntress collector agent.
- The first time data is collected it will take about 30 minutes to appear in your Huntress portal.
Note that Huntress provides third party vendor instructions as a best effort to expedite onboarding. Vendor documentation and versions frequently change and so it may be necessary to find the appropriate documentation for syslog logging for your version of the vendor software or service.
Note the vendor links above are the latest documentation at the time of this writing.