How can I configure a syslog server on a SonicWall firewall?

Description

This article provides information on how to setup a syslog server on a SonicWall firewall. Please note: this is different than setting up an app flow server.

Resolution

Pre-requisite:

  • Ā Must have GMS server or On-Prem Analytics server installed and configured.
  • Have an Address Object Created on the Firewall for SonicWall Analytics system.

Resolution for SonicOS 7.X

This release includes significantĀ user interface changes and many new features that are different from the SonicOS 6.5 and earlier firmware. The below resolution is for customers using SonicOS 7.X firmware.

Ā 

  1. Navigate to Device|Log|Syslog
  2. Select Syslog Servers and Click on Add

    Image
  3. Select theĀ Name or IP address of the Syslog server from the dropdown.

    Image
  4. SelectĀ Syslog FormatĀ as 'Enhanced'.
  5. Click ā€˜OK’.

Ā 

For testing, set upĀ packet capture based on syslog port UDP 514Ā and generate traffic based on the event type.

  1. Navigate toĀ Monitor|Tools &Ā  Monitor|Packet Monitor
  2. Navigate toĀ Advanced monitor filterĀ tab and enable all the check boxes
  3. Click on Save and start the packet capture

    Image

Ā 

Test Results snap:
Image

Ā 

  • Here, Source 192.168.x.x is the firewall generating the syslog traffic and forwarding it to the syslog server 192.168.x.x on UDP port 514.

Ā 

Resolution for SonicOS 6.5

This release includes significantĀ user interface changes and many new features that are different from the SonicOS 6.2 and earlier firmware. The below resolution is for customers using SonicOS 6.5 firmware.

Ā 

Configuration

  1. Login to the SonicWall firewall as admin.
  2. Navigate to Manage | Log Settings | SYSLOG .

    Image

  3. Under Syslog tab, Click on the AddĀ button.
    Image
  4. Ā Select the Name or IP address of the Syslog server from the dropdown.
  5. Select Syslog Format as 'Enhanced'.
  6. Click ā€˜OK’.
  7. After a couple of seconds, newly added Syslog server will show up.

    NOTE: To set syslog settings using templates, please follow:Ā 191018135555494.

    Ā 

Issue ID

SW5106

Related Articles

  • SonicOS 8.1.0 FAQ
    Read More
  • SonicWall GEN8 TZs and GEN8 NSas Settings Migration
    Read More
  • Getting started with SonicWall firewalls
    Read More
not finding your answers?