SnapGear Firewall
ArchivedThe SnapGear Firewall application normalizesSnapGear Firewall events and enables you to analyze SnapGear Firewalldata. You can further customize the searches to perform in-depth analysis.
Release Details
Package Details
- Normalization Package
- LP_SnapGear Firewall
Enhancement
A minor update has been done in the application’s normalizer for better signature handling.
Installation
Follow these steps to install the SnapGear Firewall v5.0.0 application:
- Download the SnapGear Firewall from the Download section above.
- Add the required SnapGear Firewall as a device in LogPoint.
- Create a collection policy with the Syslog collector and appropriate processing policy.
- Assign the policy to the device.
Log Format
Expected log format:
SnapGear Firewall
Log Sample
Jan 31 00:09:02 login[32161]: Authentication attempt failed for root from 192.168.2.1 because: Bad Password
To export data to LogPoint, use Syslog collector on port 514 on the LogPoint server.
Expected log format:
SnapGear Firewall
Log Sample
Jan 31 00:09:02 login[32161]: Authentication attempt failed for root from 192.168.2.1 because: Bad Password
To export data to LogPoint, use Syslog collector on port 514 on the LogPoint server.
Support
If you have any questions or require assistance, create a support ticket.
Comments
Article is closed for comments.