# SonicWall Network (syslog)

In this guide, you will set up the SonicWall connector within Radiant Security. This guide also provide steps for syslog configuration on the firewall itself. This is required in order to forward SonicWall logs to Radiant Security.

{% hint style="info" %}
**Note**: SonicWall does not have the capability of sending logs using TCP and Secure Syslog without the use of an intermediary syslog relay server.
{% endhint %}

### **Prerequisites**

* [ ] SonicWall: Full Admin User in Config Mode

### Add the data connector in Radiant Security

1. Log in to [Radiant Security](https://app.radiantsecurity.ai/).
2. From the navigation menu, click **Settings** > **Data Connectors** and click **+ Add Connector**.
3. Search for and select the **Radiant Agent** option and then click **Data Feeds.**
4. Under **Select your data feeds**, select **SonicWall Firewall Syslog** and then click **Credentials.**
5. Under **Credential Name,** give the credential an identifiable name (e.g. `Radiant Agent Integration`). If you already have a Radiant Agent in place, select it from the drop-down menu.
6. Click **Add Connector.**

### Configure a local Radiant Security Agent

Refer to the [Install the Radiant Security Agent](https://help.radiantsecurity.ai/radiant-connectors/data-connectors/install-the-radiant-security-agent) guide to set up a local agent to collect the logs.

### Configure the SonicWall Firewall

1. Login to your SonicWall Firewall.
2. On the top navigation bar, click **Device.**

<figure><img src="https://2439665791-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FPsFulb2ZOtSPcRSc2rXE%2Fuploads%2FackvIi0vqZ3Y8MT7L0rN%2FSonicWall_Network_05.webp?alt=media&#x26;token=ec5f2825-b2f8-4092-924e-c4edde6c4800" alt=""><figcaption></figcaption></figure>

3. On the left navigation list, click **Log > Settings.**

<div align="left"><figure><img src="https://2439665791-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FPsFulb2ZOtSPcRSc2rXE%2Fuploads%2Fxe8L7HtZS4HrVGyru9s7%2FSonicWall_Network_06.webp?alt=media&#x26;token=8345f73b-6be5-4c86-9d70-25851f852878" alt=""><figcaption></figcaption></figure></div>

4. Set the **Logging Level** as **Informative,** and the **Alert Level** as **Alert.** Click **Accept** to save the changes.

<figure><img src="https://2439665791-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FPsFulb2ZOtSPcRSc2rXE%2Fuploads%2Fs7w8gvaP5TeGoODVYSXX%2FSonicWall_Network_07.webp?alt=media&#x26;token=90132daa-e0dc-40e3-ac66-e7feaf2f937e" alt=""><figcaption></figcaption></figure>

<figure><img src="https://2439665791-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FPsFulb2ZOtSPcRSc2rXE%2Fuploads%2F6uGQE0hhxcKA536gpgMP%2FSonicWall_Network_08.webp?alt=media&#x26;token=2c3da94f-b344-4ea2-9715-608d888d343c" alt=""><figcaption></figcaption></figure>

5. On the **Category** column, expand the **Network** category and then expand **TCP.**
6. Enable the **Syslog** toggle for the following entries, while leaving the rest as default:
   * **TCP LAN DENY**
   * **TCP Connection Reject**
   * **TCP Connection Abort**
7. On the **TCP Connection Reject** and **TCP Connection Abort** entries, click the **debug** text under the **Priority** column, and change it to **inform**.

<figure><img src="https://2439665791-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FPsFulb2ZOtSPcRSc2rXE%2Fuploads%2FLGTVqLnJyH5p9HSlhLR0%2FSonicWall_Network_09.webp?alt=media&#x26;token=9a9197c6-d63b-4c9a-b8c0-61f344c976f5" alt=""><figcaption></figcaption></figure>

8. Still under **Network,** expand the **UDP** category to make sure the three entries have the **Syslog** toggle enabled. If not, enable all three of them.

<figure><img src="https://2439665791-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FPsFulb2ZOtSPcRSc2rXE%2Fuploads%2FnvyF0BzRDO25QHCVAoTm%2FSonicWall_Network_10.webp?alt=media&#x26;token=44a64e60-98d0-43c2-9904-222bf694fa89" alt=""><figcaption></figcaption></figure>

9. Click **Accept** to save the changes.
10. On the left navigation list, click **Log > Syslog.**

<div align="left"><figure><img src="https://2439665791-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FPsFulb2ZOtSPcRSc2rXE%2Fuploads%2FMfyhsFe8BWQLKjt68zo3%2FSonicWall_Network_11.webp?alt=media&#x26;token=86bbfae3-5856-459e-9e7e-3cbc88c02bee" alt=""><figcaption></figcaption></figure></div>

11. Click **Enhanced Syslog Fields Settings** and verify that each field is toggled on. Click **Save.**

<div align="left"><figure><img src="https://2439665791-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FPsFulb2ZOtSPcRSc2rXE%2Fuploads%2FExfK1ZoWPodAaB3DBN7W%2FSonicWall_Network_12.webp?alt=media&#x26;token=73acf381-7495-457c-8488-4a152ccfd4f0" alt="" width="563"><figcaption></figcaption></figure></div>

12. Click **Syslog Servers,** and then click **Add**. Fill in the page with the following details:
    * **Event Profile**: 0
    * **Name or IP Address**: Enter the name or IP address of your syslog server.
13. Click **Create an Address Object** and add the following settings:
    * **Name**: `Radiant Security Syslog Connector`
    * **Zone** **Assignment**: LAN
    * **Type**: Host
    * **IP** **Address**: Enter the **IP** **address** of your local Radiant Agent deployed previously.

<figure><img src="https://2439665791-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FPsFulb2ZOtSPcRSc2rXE%2Fuploads%2FoaU3JP77tYcPvwMYLD0G%2FSonicWall_Network_13.webp?alt=media&#x26;token=99c7fd89-d2ef-45e0-8ae7-c5051c270bf8" alt=""><figcaption></figcaption></figure>

14. Click **Save** and then click **Go Back.**&#x20;
15. Continue adding the remaining settings:
    * **Port**: Enter the port configured in your Radiant Agent to receive SonicWall Firewall data &#x20;
    * **Server Type**: Syslog Server
    * **Syslog Format**: Enhanced Syslog
    * **Syslog Facility**: Local use 0
    * **Syslog ID**: Leave it empty
    * **Enable Event Rate Limiting**: Disabled
    * **Enable Data Rate Limiting**: Disabled
16. Click **Add** to save your changes.&#x20;

<div align="left"><figure><img src="https://2439665791-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FPsFulb2ZOtSPcRSc2rXE%2Fuploads%2FTYR33cokZYg9xEAYzFTL%2FSonicWall_Network_14.webp?alt=media&#x26;token=8b3d8a96-7425-4305-8170-0de9bda8655c" alt="" width="410"><figcaption></figcaption></figure></div>


---

# Agent Instructions: Querying This Documentation

If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter:

```
GET https://help.radiantsecurity.ai/radiant-connectors/data-connectors/sonicwall-network-syslog.md?ask=<question>
```

The question should be specific, self-contained, and written in natural language.
The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
