Genua Firewall
ArchivedThe Genua Firewall application normalizes Genugate events and enables you to analyze Genugate data. You can further customize the searches to perform an in-depth analysis.
Release Details
Package Details
- Normalization Package
- LP_Genua Firewall
Installation
Follow these steps to install the Genua Firewall v5.0.0 application:
- Download the Genua Firewall package from the Download section above.
- Add the required Genua Firewall server as a device in LogPoint.
- Create a collection policy with the Syslog collector and an appropriate processing policy.
- Assign the policy to the device.
Log Format
Genua Firewall
Expected Log Format
Key = Value with a space as delimiter
Log Sample
<54>Feb 14 10:09:17 xxxxx udprelay[3817]: I4102 1550135357 disconnect baddr=xxx.xxx.x.xx bport=12345 caddr=xxx.xxx.x.xx cin=123 cout=456 cport=45678 duration=8.77 laddr=xxx.xxx.x.xx lport=1 paddr=xxx.xxx.x.xx pport=11 proto=12 relay_name=xxxxx rnum=789 saddr=xxx.xxx.x.xxx sin=314 sout=314 sport=53 status=OK
To export data to LogPoint, use the Syslog collector on port 514 of the LogPoint server.
Support
If you have any questions or require assistance, create a support ticket.
Comments
Article is closed for comments.