Sonicwall Firewall Log Reference
Log Samples
Learn what raw SonicWall Firewall events look like before they're processed in Logpoint. SonicWall Firewall logs typically follow a syslog format with key-value pairs.
Example Log Format:
<priority>timestamp firewall_name field1=value1 field2=value2 field3=value3 ...Field Mapping
SonicWall Firewall fields are mapped to Logpoint standardized fields for consistent analysis.
Common Field Mappings (Examples):
SonicWall source address fields →
source_addressSonicWall destination address fields →
destination_addressSonicWall source port fields →
source_portSonicWall destination port fields →
destination_portSonicWall action fields →
actionSonicWall user fields →
userSonicWall severity fields →
severitySonicWall message fields →
messageSonicWall protocol fields →
protocol
Event Categories
SonicWall Firewall events are categorized for easier analysis:
Traffic Events: Connection tracking, session management, traffic flows
Security Events: Threat detection, intrusion attempts, malicious activity
User Events: Authentication, login/logout, user sessions
Administrative Events: Configuration changes, system modifications
IPS Events: Intrusion prevention system detections
Bandwidth Events: Data transfer, bandwidth consumption
Last updated
Was this helpful?