Splunk Enterprise Security

How to get syslog from a unpopular firewall ?There is no add-on or app support for it in splunkbase.

chamjo
New Member

Hello guys:

I'm going to get log from my firewall ,in order to see more firewall information in my splunk enterprise 7.2.0 web-site,especially compliance(eg:HIPPA SOX PCI-DSS,etc) information.
But my firewall is produced by a unpopular company,not Cisco ASA、check point、fortigate etc, I can't find any add-on or app for my device in splunkbase.
so what add-on/app should I use?

Thx a lot.

0 Karma

nickhills
Ultra Champion

If there is no readily available app, you will have to build one.
This is not as daunting as it sounds, but you need to understand the logs.

If you are able to post some samples, (with any headers) we may be able to help you make a start.
What firewall is it?

If my comment helps, please give it a thumbs up!
0 Karma

lakshman239
SplunkTrust
SplunkTrust

If the firewall supports sending syslog, you can setup a syslog-ng or rsyslog on a linux server (VM could do) to receive the logs and parse them to files/folder structure. You may then have to do custom TA to extract fields for your needs.

0 Karma
Get Updates on the Splunk Community!

Observability Highlights | January 2023 Newsletter

 January 2023New Product Releases Splunk Network Explorer for Infrastructure MonitoringSplunk unveils Network ...

Security Highlights | January 2023 Newsletter

January 2023 Splunk Security Essentials (SSE) 3.7.0 ReleaseThe free Splunk Security Essentials (SSE) 3.7.0 app ...

Platform Highlights | January 2023 Newsletter

 January 2023Peace on Earth and Peace of Mind With Business ResilienceAll organizations can start the new year ...