WatchGuard Firebox Firewall Log Collection
In this document, we’ll identify the initial setup steps to collect logs from the WatchGuard Firebox Firewall. Over time, Blumira will recommend modifications to these configurations depending on output.
For vendor documentation, please click here.
Configuring Syslog and an Output Destination
- Select System > Logging.
The Logging page appears.
- Click the Syslog Server tab.
- Select the Send log messages to these syslog servers check box.
- Click Add.
The Syslog Server dialog box appears.
- In the IP Address text box, type the server IP address of the Blumira Sensor.
- In the Port text box, the default syslog server port (514) appears. To change the server port, type or select a different port for your server.
- From the Log Format drop-down list, select Syslog
- Click OK.
- (Optional) In the Description text box, type a description for the server.
- To include the date and time that the event occurs on your Firebox in the log message details, select the The time stamp check box.
- Do not check the box to include the device serial number
- In the Syslog Settings section, for each type of log message, select a syslog facility from the drop-down list.
- For high-priority syslog messages, such as alarms, select Local0.
- To assign priorities for other types of log messages (lower numbers have greater priority), select Local1 – Local7.
- To not send details for a message type, select NONE.
- To restore the default settings, click Restore Defaults.
- Click Save.
At this point the Blumira sensor will start receiving syslog communication from your WatchGuard Firebox Firewall.