Configuring Barracuda

Adding a Normalization Policy for Barracuda

  1. Go to Settings >> Configuration from the navigation bar and click Normalization Policies.

  2. At the top left, click Add.

  3. Enter a Policy Name.

  4. In Compiled Normalizer, select BarracudaCompiledNormalizer.

  5. In Normalization Packages, select the required normalization package(s).

  6. Click Submit.

_images/norm1bar.png

Adding a Normalization Policy

Adding Barracuda as a Device in Logpoint

  1. Go to Settings >> Configuration from the navigation bar and click Devices.

  2. At the top left, click Add.

  3. Enter a device Name.

  4. Enter the IP address(es) of the Barracuda server.

  5. Select the Device Groups.

  6. Select an appropriate Log Collection Policy for the logs.

  7. Select a collector or a forwarder from the Distributed Collector drop-down.

Note

It is optional to select the Device Groups, the Log Collection Policy and the Distributed Collector.

  1. Select a Time Zone. The timezone of the device must be same as its log source.

  2. Configure the Risk Values for Confidentiality, Integrity and Availability used to calculate the risk levels of the alerts generated from the device.

  3. Click Submit.

Create Device Panel

Adding Barracuda as a Device

Configuring the Syslog Collector for Barracuda

  1. Go to Settings >> Configuration from the navigation bar and click Devices.

  2. Search for the previously added device.

  3. Click the Add icon from Actions.

  4. Click Syslog Collector on AVAILABLE COLLECTORS FETCHERS.

Syslog Collector Panel

Available Collectors Fetchers Panel

  1. Select Syslog Parser as Parser.

  2. Select a Processing Policy that uses the previously created normalization policy.

  3. Select the Charset.

  4. In Proxy Server, select None

  5. Click Submit.

Available Collectors Fetchers Panel

Configuring Syslog Collector


Helpful?

We are glad this guide helped.


Please don't include any personal information in your comment

Contact Support