<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Sidewinder firewall in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Sidewinder-firewall/m-p/32307#M5737</link>
    <description>&lt;P&gt;You should be able to set a syslog source from the sidewinder console.&lt;/P&gt;

&lt;P&gt;Monitor &amp;gt; Firewall Reporter /syslog&lt;/P&gt;

&lt;P&gt;use the export audit to syslog section at the bottom&lt;/P&gt;

&lt;P&gt;click the plus&lt;/P&gt;

&lt;P&gt;enter the ip address and facility (not sure it matters)&lt;/P&gt;

&lt;P&gt;enable and save.&lt;/P&gt;

&lt;P&gt;you will see events hitting your splunk server, just make sure to define a UDP input on port 514 and then set the sourcetype of the logs to something that is meaningful if you have other sources using that indexer or input.&lt;/P&gt;

&lt;P&gt;&lt;A href="https://kc.mcafee.com/resources/sites/MCAFEE/content/live/PRODUCT_DOCUMENTATION/21000/PD21665/en_US/fe_70102_rn_a.pdf" rel="nofollow"&gt;https://kc.mcafee.com/resources/sites/MCAFEE/content/live/PRODUCT_DOCUMENTATION/21000/PD21665/en_US/fe_70102_rn_a.pdf&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 02 Sep 2010 05:47:52 GMT</pubDate>
    <dc:creator>ericpartington1</dc:creator>
    <dc:date>2010-09-02T05:47:52Z</dc:date>
    <item>
      <title>Sidewinder firewall</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sidewinder-firewall/m-p/32305#M5735</link>
      <description>&lt;P&gt;I want to get logs and data from my sidewinder firewall running 7.0.0.06.  How do I do it?&lt;/P&gt;</description>
      <pubDate>Wed, 18 Aug 2010 01:18:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sidewinder-firewall/m-p/32305#M5735</guid>
      <dc:creator>wrightp</dc:creator>
      <dc:date>2010-08-18T01:18:39Z</dc:date>
    </item>
    <item>
      <title>Re: Sidewinder firewall</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sidewinder-firewall/m-p/32306#M5736</link>
      <description>&lt;P&gt;a brief Googling session yielded this:&lt;/P&gt;

&lt;P&gt;&lt;A href="https://kc.mcafee.com/corporate/index?page=content&amp;amp;id=KB61298&amp;amp;cat=CORP_SIDEWINDER&amp;amp;actp=LIST" rel="nofollow"&gt;https://kc.mcafee.com/corporate/index?page=content&amp;amp;id=KB61298&amp;amp;cat=CORP_SIDEWINDER&amp;amp;actp=LIST&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;which suggests that there is an 'export' script that you could use. i suggest you review the documentation for Sidewinder to see if there are any other ways to get the logs out of it. the best option is probably to find out where Sidewinder writes its logs and point Splunk at that location using the information in &lt;/P&gt;

&lt;P&gt;&lt;A href="http://www.splunk.com/base/Documentation/latest/Admin/Monitorfilesanddirectories" rel="nofollow"&gt;http://www.splunk.com/base/Documentation/latest/Admin/Monitorfilesanddirectories&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Aug 2010 03:48:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sidewinder-firewall/m-p/32306#M5736</guid>
      <dc:creator>piebob</dc:creator>
      <dc:date>2010-08-18T03:48:01Z</dc:date>
    </item>
    <item>
      <title>Re: Sidewinder firewall</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sidewinder-firewall/m-p/32307#M5737</link>
      <description>&lt;P&gt;You should be able to set a syslog source from the sidewinder console.&lt;/P&gt;

&lt;P&gt;Monitor &amp;gt; Firewall Reporter /syslog&lt;/P&gt;

&lt;P&gt;use the export audit to syslog section at the bottom&lt;/P&gt;

&lt;P&gt;click the plus&lt;/P&gt;

&lt;P&gt;enter the ip address and facility (not sure it matters)&lt;/P&gt;

&lt;P&gt;enable and save.&lt;/P&gt;

&lt;P&gt;you will see events hitting your splunk server, just make sure to define a UDP input on port 514 and then set the sourcetype of the logs to something that is meaningful if you have other sources using that indexer or input.&lt;/P&gt;

&lt;P&gt;&lt;A href="https://kc.mcafee.com/resources/sites/MCAFEE/content/live/PRODUCT_DOCUMENTATION/21000/PD21665/en_US/fe_70102_rn_a.pdf" rel="nofollow"&gt;https://kc.mcafee.com/resources/sites/MCAFEE/content/live/PRODUCT_DOCUMENTATION/21000/PD21665/en_US/fe_70102_rn_a.pdf&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Sep 2010 05:47:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sidewinder-firewall/m-p/32307#M5737</guid>
      <dc:creator>ericpartington1</dc:creator>
      <dc:date>2010-09-02T05:47:52Z</dc:date>
    </item>
  </channel>
</rss>

