WatchGuard Firewall (syslog)
Configure WatchGuard Firewall for syslog log forwarding to Radiant Security.
In this guide, you will configure syslog log forwarding for WatchGuard Firewall.
Add the data connector in Radiant Security
Log in to Radiant Security.
From the navigation menu, click Settings > Data Connectors and click + Add Connector.
Search for and select the WatchGuard Firewall option and then click Data Feeds.
Under Select your data feeds, select the WatchGuard Firewall data feed and click Credentials.
Under Credential Name, give the credential an identifiable name (e.g.
Firebox - Token). If you already have a credential in place, select it from the drop-down menu. Click Add Connector.In the Connector tag field, enter a random value. This value will act as the salt to randomize the unique Token you’ll download in the next step.
Click Add Connector.
Click Done to save your changes.
Configure a local Radiant Security Agent
Refer to the Install the Radiant Security Agent guide to set up a local agent to collect the logs.
Configure log forwarding with WatchGuard Firewall
You can configure your WatchGuard Firebox to send log messages to a syslog server using either the Fireware Web UI or Policy Manager. Multiple syslog servers are supported in Fireware v12.4 and higher for locally-managed Fireboxes.
Follow the steps bellow or refer to WatchGuard Syslog Configuration Guide for more information.
Select System > Logging.
Click the Syslog Server tab.
Select the Send log messages to these syslog servers check box.
Click Add.
In the IP Address text box, type the IP address of the local Radiant Security Agent syslog forwarder.
In the Port text box, type the Radiant Security Agent local Agent port.
From the Log Format drop-down list, select Syslog.
In the Description text box, type a description for the server (e.g.,
Radiant Security Connector).Check the
time stampandserial numbercheck boxes.In the Syslog Settings section, leave the default values except for Performance, which should be None.
Alarm: Local0
Traffic: Local1
Event: Local2
Diagnostic: Local3
Performance: None
Click Save.
Last updated