SonicWall Firewall Integration Guide🔗
SonicWall firewalls must be configured to send logs via syslog to the Taegis™ XDR Collector.
Connectivity Requirements🔗
| Source | Destination | Port/Protocol |
|---|---|---|
| SonicWall | XDR Collector (mgmt IP) | UDP/514 |
Data Provided from Integration🔗
| Normalized Data | Out-of-the-Box Detections | Vendor-Specific Detections | |
|---|---|---|---|
| SonicWall Firewall | DHCP | Auth, DNS, HTTP, Netflow | NIDS |
Note
XDR detectors are not guaranteed to be triggered, even if a data source's logs are normalized to a schema associated with a given detector. However, you can create Custom Detection Rules to generate detections based on normalized data from a data source.
Logging Configuration Instructions🔗
To configure the SonicWall SonicOS syslog, follow the guide provided by SonicWall. Ensure you complete the following fields with the correct values:
