WatchGuard Firewall
Connect WatchGuard Firewall to Radiant Security to forward syslog for AI triage.
WatchGuard Firewall (Firebox) is a network firewall and unified threat management appliance that inspects perimeter traffic and blocks intrusions, malware, and policy violations. Connecting WatchGuard Firewall forwards firewall traffic, intrusion alerts, and diagnostic logs to Radiant Security via syslog through the Radiant Agent. Radiant uses these logs for AI triage, giving analysts perimeter context for verdicts on suspicious network activity.
Prerequisites
Add the data connector in Radiant Security
Log in to Radiant Security.
From the navigation menu, click Settings > Data Connectors, then click + Add Connector.
Search for and select Radiant Agent, then click Data Feeds.
Under Select your data feeds, select WatchGuard Firebox Firewall, then click Credentials.
Under Credential Name, enter an identifiable name for the Radiant Agent integration (e.g.,
Radiant Agent integration). To reuse an existing Radiant Agent credential, select it from the drop-down menu.Click Add Connector.
Configure WatchGuard Firebox to forward syslog
Before starting, confirm the IP address of the Radiant Agent and the port configured to receive WatchGuard Firewall data. If you do not know the port, contact your Customer Success representative.
For vendor instructions, refer to WatchGuard's Send Log Messages to a Syslog Server guide. Multiple syslog servers are supported in Fireware v12.4 and higher for locally-managed Fireboxes.
In Fireware Web UI or Policy Manager, select System > Logging
Click the Syslog Server tab.
Select the Send log messages to these syslog servers checkbox.
Click Add.
In the IP Address field, enter the IP address of the Radiant Agent.
In the Port field, enter the port configured on the Radiant Agent to receive WatchGuard Firewall data.
From the Log Format drop-down list, select Syslog.
In the Description field, enter a description for the server (e.g.,
Radiant Security Connector).Select the Time Stamp and Serial Number checkboxes.
In the Syslog Settings section, leave the default facility values and set Performance to None:
Alarm: Local0
Traffic: Local1
Event: Local2
Diagnostic: Local3
Performance: None
Click Save.
Verify ingestion
After WatchGuard Firewall begins forwarding, confirm alerts and events are reaching Radiant.
In Radiant, navigate to Log Management.
Filter by
rs_connectorType:"watchguard_firebox".Confirm recent alerts and events appear.
Allow several minutes for alerts and events to be parsed, indexed, and available for search.
Last updated
Was this helpful?