Logo
Resources
Documentation Portal Ideas Portal Guardsix Academy License Portal
Resources
Documentation Portal Ideas Portal Guardsix Academy License Portal
Sign in
  1. Guardsix Servicedesk
  2. Products Hub
  3. Marketplace

SonicWall Firewall

Standard

SonicWall Firewall normalizes SonicWall Firewall events. LogPoint aggregates and normalizes the SonicWall Firewall logs so you can analyze the information and monitor the security status of your organization through dashboard. The SonicWall Firewall dashboard provides visualization of event details for malicious IP addresses, severities, user activities, bandwidth usage, and administrative tasks detected by the firewall on your network. You can customize the dashboard to suit your needs and perform in-depth analysis by adjusting the data and searches.

Release Details

Version: 5.1.0
Release date: 2022-04-13
Supported On: 6.7.0 or later
SHA 256: b3693437db496e2a844aa63af564c661fa25d01b5fcaafea037431893b6fd7ea
Download

Enhancements

KB-1618962864
Changed the severity field to log_level in the SonicWall Firewall logs to maintain consistency with other application packages.
Made the following changes in the SoniceWall Firewall VPN logs to make it compatible for LogPoint UEBA: Added the VPN label. Added the User and Authentication labels. Added the status field.
KB-16379

Renamed the following fields to maintain consistency:

  • packet_sent to sent_packet
  • packet_received to received_packet
  • bytesTotal to datasize
  • bytesOut to sent_datasize
  • bytesIn to received_datasize
  • packetsTotal to packet
  • packetsIn to received_packet
  • packetsOut to sent_packet

Bug Fix

The user field in the SoniceWall Firewall VPN logs previously captured the user details instead of username.

Installation

To install SonicWall Firewall v5.1.0:

  1. Download the .pak file from the Download section in the Release Details table.
  2. Add SonicWall Firewall as a device in LogPoint.
  3. Create a collection policy with the Syslog collector and an appropriate processing policy.
  4. Assign the policy to the device.
  5. Add the dashboard.

Past Releases

Changes in SonicWall Firewall v5.0.2 ▾
Version: 5.0.2

Enhancement

KB-1397658677
The field agent has been renamed as user_agent for the VPN logs in the compiled normalizer SonicFirewallCompiledNormalizer .

Bug Fix

KB-1397658677
An issue in the compiled normalizer SonicFirewallCompiledNormalizer where some VPN logs were not normalized.
6.0.0 to 6.6.6 ▾
Version: 3.4.0
Release date: 2020-05-14
Supported On: 6.0.0 to 6.6.6
SHA 256: 6a089c8cf580701774820dcb5673d46b2d4de833842d2af96a11c1e6a7476ea5
Download

Enhancement

A minor update has been done in the application’s normalizer for better signature handling.

Log Formats

Expected Log Format Sample

SonicWall VPN 

id=sslvpn sn=C0EAE49CC0F0 time="2022-01-20 04:00:23" fw=1.1.1.1 pri=5 c=16 m=526 msg="Web management request allowed" dur=0 n=12345678 src=1.1.1.3:123456:X0 dst=1.1.1.3:80:X1 user_agent=abc.net proto=tcp/http sent=48 dpi=0 fw_action="NA"'

<134>id=firewall sn=xxxxx fw=1.1.1.5 time="2022-01-19 18:05:44" pri=1 c=32 m=609 msg="IPS Prevention Alert: DNS named version attempt" sid=143 ipscat=DNS ipspri=3 n=3 src=1.1.1.1 dst=1.1.1.4

Expected Log Format Sample

SonicWall Aventail

Jul 2 09:22:15 AventailSSLVPN-node2 logserver: [02/Jul/2018:09:19:15.380825 +0200] AventailSSLVPN-node2 000000 kt 00000000 Info Audit Src='192.168.1.1:4912' Auth='-' User='(xxxxx)@(LBW Inern)' SocksVersion='0x101' Command='Flow:TCP' Dest='19.26.219.132:445' Error='0xffffff92' SrcBytes='152' DstBytes='0' Duration='70' VirtualHost='-' PlatformPrefix='W' EquipmentId='3S70WNHA433' AppNumber='0'

Expected Log Format Sample

SonicWall Firewall

id=firewall sn=xxxxx fw=192.168.2.15 time="2016-08-19 18:05:44" pri=1 c=32 m=609 msg="IPS Prevention Alert: DNS named version attempt" sid=143 ipscat=DNS ipspri=3 n=3 src=192.168.3.180:2907 dst=192.168.2.11:53

Documentation

The SonicWall Firewall v5.1.0 guide  is available on the LogPoint Documentation Portal. 

Support

If you have any questions or require assistance, create a support ticket.

  • SonicWallFirewall.zip (1 MB)

Comments

Article is closed for comments.

Follow

Related articles

  • Sophos
  • Universal Normalizer
  • Microsoft Dynamic NAV
  • ChatGPT Integration
  • Netgear Firewall
Consent Required To Proceed
By clicking “I Agree & Download”, you confirm that you are authorized to act on behalf of your organization and you give explicit consent for Guardsix to share your organization’s customer name and log source count with NXLog for the sole purposes of entitlement management, compliance verification, and support delivery related to the embedded NXLog technology in the Guardsix SIEM solution.

This data will not be used for sales or marketing and will not be shared with other third parties. You may withdraw your consent at any time by contacting Guardsix Support; withdrawal will not affect processing already performed.
Cancel I Agree & Download
Privacy policy    EULA    Terms of service   
Copyright © , Guardsix. All rights reserved.

Note: We use cookies that are essential for the smooth functioning of our website.