Security

firewall logs

mohammadnreda
New Member

hello every one

i had sangfor firewall, and there is no addon on splunk for it,

so what is the method to get firewall logs on splunk

thanks

Labels (1)
0 Karma

emdaax
Explorer

Hi @mohammadnreda,

I would recommend following some general steps to ingest your logs via Syslog. There are multiple ways to get Syslog data into Splunk, and the current best practice is to use "Splunk Connect for Syslog (SC4S)." This is a containerized Syslog-ng server with a configuration framework designed to simplify the process of getting Syslog data into both Splunk Enterprise and Splunk Cloud.

If you already have a dedicated Syslog server (such as rsyslog or Syslog-ng), you simply need to enable Syslog forwarding from your Sangfor Firewall to the Syslog collector. From there, use a Universal Forwarder instance to read and forward your Syslogs to an indexer.

Some useful links:

 

There is also an older post about Sangfor Firewall (answered by gcusello) that might be helpful for you:

 

best regards,

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @mohammadnreda,

I suppose that you're receivig your firewall logs by syslog.

So you have to create your custom add-on to parse your logs.

If you need to use them in ES or ITSI you have also to nomalize them and the Splunk Add-On Builder (https://splunkbase.splunk.com/app/2962) can help you in normalization.

If instead you have only tro monitor your firewalls, you can only parse your logs to extract all the relevant fields to use in dashboards.

Anyway, my hint is to normalize your logs to have a custom CIM 4.x compliant add-on.

Ciao.

Giuseppe

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...