Getting Data In

Sidewinder firewall

wrightp
New Member

I want to get logs and data from my sidewinder firewall running 7.0.0.06. How do I do it?

Tags (2)
0 Karma

ericpartington1
Engager

You should be able to set a syslog source from the sidewinder console.

Monitor > Firewall Reporter /syslog

use the export audit to syslog section at the bottom

click the plus

enter the ip address and facility (not sure it matters)

enable and save.

you will see events hitting your splunk server, just make sure to define a UDP input on port 514 and then set the sourcetype of the logs to something that is meaningful if you have other sources using that indexer or input.

https://kc.mcafee.com/resources/sites/MCAFEE/content/live/PRODUCT_DOCUMENTATION/21000/PD21665/en_US/...

piebob
Splunk Employee
Splunk Employee

a brief Googling session yielded this:

https://kc.mcafee.com/corporate/index?page=content&id=KB61298&cat=CORP_SIDEWINDER&actp=LIST

which suggests that there is an 'export' script that you could use. i suggest you review the documentation for Sidewinder to see if there are any other ways to get the logs out of it. the best option is probably to find out where Sidewinder writes its logs and point Splunk at that location using the information in

http://www.splunk.com/base/Documentation/latest/Admin/Monitorfilesanddirectories

Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...