Sidewinder Firewall
ArchivedThe Sidewinder Firewall application normalizes Sidewinder Firewall events and enables you to analyze the data using pre-set dashboard views. You can further customize the dashboard and searches to perform in-depth analysis.
Release Details
Package Details
- Dashboard Package
- LP_Sidewinder Firewall
- Normalization Package
- LP_Sidewinder Firewall
- Compiled Normalizer
- SidewinderFirewallCompiledNormalizer
Enhancement
Installation
Follow these steps to install the Sidewinder Firewall v5.0.1 plugin:
- Download the Sidewinder Firewall package from the Download section above.
- Add Sidewinder Firewall as the required device in LogPoint.
- Create a collection policy with the Syslog collector and appropriate processing policy.
- Assign the policy to the device.
- Add the Dashboard.
Past Release
For LogPoint v6.0.0 to v6.6.6 ▾
Enhancement
Log Format
Expected Log Format
Key = Value separated by a comma
Log Sample
Oct 24 03:03:55 hostname.com.au auditd: date="Oct 23 17:03:55 2008 GMT",fac=f_mail,area=a_server,type=t_attack,pri=p_major,pid=11945,ruid=0,euid=0,pgid=1787,logid=0,cmd=sendmail,domain=mta1,edomain=mta1,hostname=hostname.com.au,event=access deny,srcip=1.1.1.1,srcburb=outside,attackip=2.2.2.2,attackburb=outside,queueid=m9NH3tOH011945,reason="Sendmail determined that this session is not allowed.",information="550 5.7.1 TrustedSource determined this IP address is untrusted. Reputation value: 0.0.0.10
To export data to LogPoint, use Syslog collector on port 514 on the LogPoint server.
Support
If you have any questions or require assistance, create a support ticket.
Comments
Article is closed for comments.