SonicWall Firewall Integration Guide🔗
SonicWall firewalls must be configured to send logs via syslog to the Taegis™ XDR Collector.
Connectivity Requirements🔗
Source | Destination | Port/Protocol |
---|---|---|
SonicWall | XDR Collector (mgmt IP) | UDP/514 |
Data Provided from Integration🔗
Normalized Data | Out-of-the-Box Detections | Vendor-Specific Detections | |
---|---|---|---|
SonicWall Firewall | DHCP | Auth, DNS, HTTP, Netflow | NIDS |
Note
XDR detectors are not guaranteed to be triggered, even if a data source's logs are normalized to a schema associated with a given detector. However, you can create Custom Alert Rules to generate alerts based on normalized data from a data source.
Logging Configuration Instructions🔗
To configure the SonicWall SonicOS syslog, follow the guide provided by SonicWall. Ensure you complete the following fields with the correct values: