Before you begin

Determine the Blumira sensor you will use as a syslog server to collect log data. On the sensor detail screen, under Host Details, copy the IP address of your Blumira sensor to use when configuring WatchGuard Firebox.

Configuring Syslog and an Output Destination

To configure WatchGuard Firebox to send log data to Blumira Sensor:

  1. Navigate to System > Logging.
  2. Click the Syslog Server tab.
  3. Select the Send log messages to these syslog servers check box.
  4. Click Add.
    The Syslog Server dialog box appears.
  5. In the IP Address field, type the server IP address of the Blumira Sensor.
  6. In the Port field, keep the default 514.
  7. From the Log Format drop-down list, select SyslogWatchGuard Syslog Settings
  8. Click OK.
  9. (Optional) In the Description text box, type a description for the server.
  10. To include the date and time that the event occurs on your Firebox in the log message details, select the The time stamp check box.
  11. Do not check the box to include the device serial number
  12. In the Syslog Settings section, for each type of log message, select a syslog facility from the drop-down list.
    • For high-priority syslog messages, such as alarms, select Local0.
    • To assign priorities for other types of log messages (lower numbers have greater priority), select Local1 – Local7.
    • To not send details for a message type, select NONE.
  13. To restore the default settings, click Restore Defaults.
  14. Click Save.

For vendor documentation, please click here.