Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

### Version #14085

Closed
1 task done
shooktyl opened this issue Jan 8, 2025 · 1 comment
Closed
1 task done

### Version #14085

shooktyl opened this issue Jan 8, 2025 · 1 comment

Comments

@shooktyl
Copy link

shooktyl commented Jan 8, 2025

Version

2.4.100

Installation Method

Security Onion ISO image

Description

configuration

Installation Type

Standalone

Location

on-prem with Internet access

Hardware Specs

Meets minimum requirements

CPU

4

RAM

16

Storage for /

200 GB

Storage for /nsm

200 GB

Network Traffic Collection

other (please provide detail below)

Network Traffic Speeds

Less than 1Gbps

Status

Yes, all services on all nodes are running OK

Salt Status

Yes, there are salt failures (please provide detail below)

Logs

No, there are no additional clues

Detail

Hello,

I am new to Security Onion and am hoping to use it to ingest Syslog data from my SonicWall OS 7 firewall. I have followed the following resources while configuring this:

I am attempting to use the Elastic SonicWall Firewall Syslog Integration, as recommended by the Security Onion tutorials. I isolated this to be a configuration issue on the Security Onion server. I have the SonicWall firewall configured to send Syslog data and confirmed it works via a POC Ubuntu VM running rSyslog. rSyslog captured all of the intended data. However, when querying from Elastic or Security Onion, I am unable to find any data from the SonicWall firewall.

I made the following changes under Administration/Configuration/Firewall

  • hostgroups/customhostgroup0/IP of SonicWall firewall
  • hostgroups/syslog/IP of SonicWall firewall
  • portgroups/customportgroup0/udp/UDP port for Syslog on SonicWall firewall
  • role/standalone/chain/INPUT/hostgroups/customhostgroup0/portgroups/customportgroup0

I synchronized the grid after making the changes.

Here is how I configured my SonicWall Elastic Integration:
SonicWall Elastic Integration

As requested, here is some additional information regarding my environment:

  •  SALT Status: Do you get any failures when you run "sudo salt-call state.highstate"? --> SALT error
  • Network Traffic Collection: Are you collecting network traffic from a tap or span port? --> I do not believe I have the second NIC working correctly on my vSphere VM.

 
Has anyone been successful in configuring the SonicWall Syslog integration in their environment? Any tips or guidance would be greatly appreciated, this looks like such a useful tool! Please let me know what additional information to provide.

Guidelines

Originally posted by @sysadmin-sec in #13929

@shooktyl
Copy link
Author

shooktyl commented Jan 8, 2025

@shooktyl shooktyl closed this as completed Jan 8, 2025
@github-actions github-actions bot locked as resolved and limited conversation to collaborators Feb 8, 2025
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant