SonicWall Elastic Agent Syslog Elastic Integration Not Passing Data to Security Onion/Elastic #13929
-
Version2.4.100 Installation MethodSecurity Onion ISO image Descriptionconfiguration Installation TypeStandalone Locationon-prem with Internet access Hardware SpecsMeets minimum requirements CPU4 RAM16 Storage for /200 GB Storage for /nsm200 GB Network Traffic Collectionother (please provide detail below) Network Traffic SpeedsLess than 1Gbps StatusYes, all services on all nodes are running OK Salt StatusYes, there are salt failures (please provide detail below) LogsNo, there are no additional clues DetailHello, I am new to Security Onion and am hoping to use it to ingest Syslog data from my SonicWall OS 7 firewall. I have followed the following resources while configuring this:
I am attempting to use the Elastic SonicWall Firewall Syslog Integration, as recommended by the Security Onion tutorials. I isolated this to be a configuration issue on the Security Onion server. I have the SonicWall firewall configured to send Syslog data and confirmed it works via a POC Ubuntu VM running rSyslog. rSyslog captured all of the intended data. However, when querying from Elastic or Security Onion, I am unable to find any data from the SonicWall firewall. I made the following changes under Administration/Configuration/Firewall
I synchronized the grid after making the changes. Here is how I configured my SonicWall Elastic Integration: As requested, here is some additional information regarding my environment:
Guidelines
|
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 1 reply
-
Try using a different port, rather than 514 -- that's configured by default for the standard syslog listener. |
Beta Was this translation helpful? Give feedback.
Try using a different port, rather than 514 -- that's configured by default for the standard syslog listener.