SonicWall Firewall
StandardSonicWall Firewall normalizes SonicWall Firewall events. LogPoint aggregates and normalizes the SonicWall Firewall logs so you can analyze the information and monitor the security status of your organization through dashboard. The SonicWall Firewall dashboard provides visualization of event details for malicious IP addresses, severities, user activities, bandwidth usage, and administrative tasks detected by the firewall on your network. You can customize the dashboard to suit your needs and perform in-depth analysis by adjusting the data and searches.
Release Details
Enhancements
Renamed the following fields to maintain consistency:
-
packet_senttosent_packet -
packet_receivedtoreceived_packet -
bytesTotaltodatasize -
bytesOuttosent_datasize -
bytesIntoreceived_datasize -
packetsTotaltopacket -
packetsIntoreceived_packet -
packetsOuttosent_packet
Bug Fix
Installation
To install SonicWall Firewall v5.1.0:
- Download the .pak file from the Download section in the Release Details table.
- Add SonicWall Firewall as a device in LogPoint.
- Create a collection policy with the Syslog collector and an appropriate processing policy.
- Assign the policy to the device.
- Add the dashboard.
Past Releases
Changes in SonicWall Firewall v5.0.2 ▾
Enhancement
Bug Fix
6.0.0 to 6.6.6 ▾
Enhancement
Log Formats
Expected Log Format Sample
SonicWall VPN
id=sslvpn sn=C0EAE49CC0F0 time="2022-01-20 04:00:23" fw=1.1.1.1 pri=5 c=16 m=526 msg="Web management request allowed" dur=0 n=12345678 src=1.1.1.3:123456:X0 dst=1.1.1.3:80:X1 user_agent=abc.net proto=tcp/http sent=48 dpi=0 fw_action="NA"'
<134>id=firewall sn=xxxxx fw=1.1.1.5 time="2022-01-19 18:05:44" pri=1 c=32 m=609 msg="IPS Prevention Alert: DNS named version attempt" sid=143 ipscat=DNS ipspri=3 n=3 src=1.1.1.1 dst=1.1.1.4
Expected Log Format Sample
SonicWall Aventail
Jul 2 09:22:15 AventailSSLVPN-node2 logserver: [02/Jul/2018:09:19:15.380825 +0200] AventailSSLVPN-node2 000000 kt 00000000 Info Audit Src='192.168.1.1:4912' Auth='-' User='(xxxxx)@(LBW Inern)' SocksVersion='0x101' Command='Flow:TCP' Dest='19.26.219.132:445' Error='0xffffff92' SrcBytes='152' DstBytes='0' Duration='70' VirtualHost='-' PlatformPrefix='W' EquipmentId='3S70WNHA433' AppNumber='0'
Expected Log Format Sample
SonicWall Firewall
id=firewall sn=xxxxx fw=192.168.2.15 time="2016-08-19 18:05:44" pri=1 c=32 m=609 msg="IPS Prevention Alert: DNS named version attempt" sid=143 ipscat=DNS ipspri=3 n=3 src=192.168.3.180:2907 dst=192.168.2.11:53
Documentation
The SonicWall Firewall v5.1.0 guide is available on the LogPoint Documentation Portal.
Support
If you have any questions or require assistance, create a support ticket.
Comments
Article is closed for comments.