Ingest Sonicwall Firewall Logs

Prerequisites

  • Logpoint: v6.7.4 or later

  • SonicWall Access: Syslog forwarding configured on SonicWall devices to send logs to Logpoint

Install SonicWall Firewall

  1. Download the .pak file from the Help Center.

  2. Install the Package

    1. Go to Settings >> System Settings from the navigation bar.

    2. Click Applications.

    3. Click Import.

    4. Browse to the downloaded .pak file.

    5. Click Upload.

  3. Verify Installation After installation, verify the integration appears under Settings >> System Settings >> Plugins.


Configure SonicWall Firewall

You can configure SonicWall Firewall using the Devices method.

Configuring a Repo for SonicWall Firewall

  1. Go to Settings >> Configuration from the navigation bar and click Repos.

  2. Click Add.

  3. Enter a Repo Name.

  4. Select a Repo Path to store incoming logs.

  5. Set a Retention Day to keep logs in a repository before they are automatically deleted.

    Note: You can add and remove multiple Repo Path and Retention Day.

  6. Select a Remote Logpoint and set a Available for (day).

  7. Click Submit.

Adding a Normalization Policy for SonicWall Firewall

Normalization policies normalize and standardize logs for efficient storage, analysis, and retrieval.

  1. Go to Settings >> Configuration from the navigation bar and click Normalization Policies.

  2. Click Add.

  3. Enter a Policy Name.

  4. Select the Compiled Normalizer for SonicWall Firewall:

    • SonicFirewallCompiledNormalizer (for standard SonicWall logs)

    • SonicWallAventailCompiledNormalizer (for SonicWall Aventail logs)

  5. Select the required Normalization Packages:

    • LP_SonicWall SMA

    • LP_SonicWall SMA Process

  6. Click Submit.

Configuring a Processing Policy for SonicWall Firewall

Processing policy dictates how SonicWall Firewall logs are handled, processed, and stored to enhance their usability and accessibility for monitoring, reporting, and alerting purposes.

  1. Go to Settings >> Configuration from the navigation bar and click Processing Policies.

  2. Click Add.

  3. Enter a Policy Name.

  4. Select the previously created normalization policy.

  5. Select the Enrichment Policy.

  6. Select the Routing Policy.

  7. Click Submit.

Adding SonicWall Firewall as a Device in Logpoint

  1. Go to Settings >> Configuration from the navigation bar and click Devices.

  2. Click Add.

  3. Enter a device Name.

  4. Enter the SonicWall Firewall server IP address(es).

  5. Select the Device Groups.

  6. Select an appropriate Log Collection Policy for the logs.

  7. Select a collector or a forwarder from the Distributed Collector drop-down.

    Note: It is optional to select the Device Groups, the Log Collection Policy and the Distributed Collector.

  8. Select a Time Zone. The timezone of the device must be same as its log source.

  9. Configure the Risk Values for Confidentiality, Integrity and Availability used to calculate the risk levels of the alerts generated from the device.

  10. Click Submit.

Configuring the Syslog Collector for SonicWall Firewall

  1. Go to Settings >> Configuration from the navigation bar and click Devices.

  2. Click the Add collectors/fetchers icon under Actions of the previously added device.

  3. Click Syslog Collector.

    Note: You can select a different collector depending on your requirements and added device. To learn more about available collectors, refer to the collectors documentation. If you require assistance, contact our support team.

  4. Select Syslog Parser as Parser.

  5. Select the previously created Processing Policy which contains the normalization policy.

  6. Select the Charset.

  7. In Proxy Server, select None (or configure proxy settings if needed).

  8. Click Submit.

Verify Ingestion

Check Log Ingestion

Use the following query to verify SonicWall Firewall logs are being ingested:

Or search by normalizer:

Verify Data Flow

  1. Check Syslog Collector Status: Ensure the SonicWall collector is running without errors.

  2. Monitor Log Volume: Verify expected log volumes are being processed.

  3. Validate Normalization: Confirm logs are correctly parsed and normalized using the SonicFirewallCompiledNormalizer or SonicWallAventailCompiledNormalizer.

  4. Test Dashboards: Access SonicWall Firewall dashboards to verify data visualization.

Last updated

Was this helpful?