<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic WatchGuard FireBox Assistance in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/WatchGuard-FireBox-Assistance/m-p/531423#M89398</link>
    <description>&lt;P&gt;Hello Everyone,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm hoping to get some assistance.&amp;nbsp; My company using WatchGuard Firebox firewalls.&amp;nbsp; I'm working to get the data correcting ingested into Splunk and get all the fields extracted (HIGHLY prefer a CIM complaint format) but the only WatchGuard App and TA Addon I've found are outdated, poorly written (I've been told) and are not CIM compliant.&amp;nbsp; Is there an easy way to pull the information from the WatchGuard Log Catalog (&lt;A href="https://www.watchguard.com/help/docs/fireware/12/en-US/log_catalog/Log-Catalog_v12_5.pdf" target="_blank" rel="noopener"&gt;https://www.watchguard.com/help/docs/fireware/12/en-US/log_catalog/Log-Catalog_v12_5.pdf&lt;/A&gt;) and put it into Splunk to properly ingest and label the data coming in from WatchGuard logs?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="AJSCSA_0-1606783212014.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/12124i707B99AD785B1B98/image-size/medium?v=v2&amp;amp;px=400" role="button" title="AJSCSA_0-1606783212014.png" alt="AJSCSA_0-1606783212014.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for any and all assistance with this!&lt;/P&gt;</description>
    <pubDate>Tue, 01 Dec 2020 00:41:31 GMT</pubDate>
    <dc:creator>AJSCSA</dc:creator>
    <dc:date>2020-12-01T00:41:31Z</dc:date>
    <item>
      <title>WatchGuard FireBox Assistance</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/WatchGuard-FireBox-Assistance/m-p/531423#M89398</link>
      <description>&lt;P&gt;Hello Everyone,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm hoping to get some assistance.&amp;nbsp; My company using WatchGuard Firebox firewalls.&amp;nbsp; I'm working to get the data correcting ingested into Splunk and get all the fields extracted (HIGHLY prefer a CIM complaint format) but the only WatchGuard App and TA Addon I've found are outdated, poorly written (I've been told) and are not CIM compliant.&amp;nbsp; Is there an easy way to pull the information from the WatchGuard Log Catalog (&lt;A href="https://www.watchguard.com/help/docs/fireware/12/en-US/log_catalog/Log-Catalog_v12_5.pdf" target="_blank" rel="noopener"&gt;https://www.watchguard.com/help/docs/fireware/12/en-US/log_catalog/Log-Catalog_v12_5.pdf&lt;/A&gt;) and put it into Splunk to properly ingest and label the data coming in from WatchGuard logs?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="AJSCSA_0-1606783212014.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/12124i707B99AD785B1B98/image-size/medium?v=v2&amp;amp;px=400" role="button" title="AJSCSA_0-1606783212014.png" alt="AJSCSA_0-1606783212014.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for any and all assistance with this!&lt;/P&gt;</description>
      <pubDate>Tue, 01 Dec 2020 00:41:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/WatchGuard-FireBox-Assistance/m-p/531423#M89398</guid>
      <dc:creator>AJSCSA</dc:creator>
      <dc:date>2020-12-01T00:41:31Z</dc:date>
    </item>
    <item>
      <title>Re: WatchGuard FireBox Assistance</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/WatchGuard-FireBox-Assistance/m-p/531746#M89443</link>
      <description>&lt;P&gt;Any chance anyone could look at this and offer some advice?&amp;nbsp; Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 02 Dec 2020 17:20:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/WatchGuard-FireBox-Assistance/m-p/531746#M89443</guid>
      <dc:creator>AJSCSA</dc:creator>
      <dc:date>2020-12-02T17:20:23Z</dc:date>
    </item>
    <item>
      <title>Re: WatchGuard FireBox Assistance</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/WatchGuard-FireBox-Assistance/m-p/546137#M90978</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;First of all, I am not a professional splunker but due to my case, I have to dig deep for some scenarios on the watchguard firebox devices.&lt;/P&gt;&lt;P&gt;Please note that, based on my experience so far on watchguard (again I am not guru) the app and add-on does not handle the fields extraction properly.&lt;BR /&gt;I just used them so far for the source type (watchguard:firebox:syslog) and I am extracting most of the fields on my own.&lt;/P&gt;&lt;P&gt;Please advise which fields do you need them the most, maybe we can help each other.&lt;/P&gt;&lt;P&gt;I am using this regular expression for for Source_IP, Destination_IP, Source_Port and Destination_Port:&lt;/P&gt;&lt;P&gt;(?&amp;lt;src_ip&amp;gt;\d+\.\d+\.\d+\.\d+) (?&amp;lt;dst_ip&amp;gt;\d+\.\d+\.\d+\.\d+) (?&amp;lt;src_portt&amp;gt;\d+) (?&amp;lt;dst_port&amp;gt;\d+)&lt;BR /&gt;So far it covers all my needs for the required searches/dashboards.&lt;BR /&gt;(do not forget the SPACES)&lt;BR /&gt;&lt;BR /&gt;Please advise if it helps you.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Wed, 31 Mar 2021 06:49:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/WatchGuard-FireBox-Assistance/m-p/546137#M90978</guid>
      <dc:creator>a_n</dc:creator>
      <dc:date>2021-03-31T06:49:47Z</dc:date>
    </item>
    <item>
      <title>Re: WatchGuard FireBox Assistance</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/WatchGuard-FireBox-Assistance/m-p/546144#M90980</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/228901"&gt;@AJSCSA&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;Do you have properly configured soucretype ?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vikramyadav_0-1617174529501.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/13552iD8CD5D7C9CDB5C9B/image-size/medium?v=v2&amp;amp;px=400" role="button" title="vikramyadav_0-1617174529501.png" alt="vikramyadav_0-1617174529501.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Also I have got one doc please try that out.&lt;BR /&gt;&lt;A href="https://www.watchguard.com/help/docs/help-center/en-US/Content/Integration-Guides/General/splunk_integration_V2.html" target="_blank"&gt;https://www.watchguard.com/help/docs/help-center/en-US/Content/Integration-Guides/General/splunk_integration_V2.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;--------------------------------------------------------------------------&lt;BR /&gt;If this helps your like will be appreciate.&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":smiling_face_with_smiling_eyes:"&gt;😊&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Mar 2021 07:11:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/WatchGuard-FireBox-Assistance/m-p/546144#M90980</guid>
      <dc:creator>vikramyadav</dc:creator>
      <dc:date>2021-03-31T07:11:27Z</dc:date>
    </item>
  </channel>
</rss>

