How can I configure a syslog server on a SonicWall firewall?

Description

This article provides information on how to setup a syslog server on a SonicWall firewall. Please note: this is different than setting up an app flow server.

Resolution

Pre-requisite:

  • Ā Must have GMS server or On-Prem Analytics server installed and configured.
  • Have an Address Object Created on the Firewall for SonicWall Analytics system.

Resolution for SonicOS 7.X

This release includes significantĀ user interface changes and many new features that are different from the SonicOS 6.5 and earlier firmware. The below resolution is for customers using SonicOS 7.X firmware.

Ā 

  1. Navigate to Device|Log|Syslog
  2. Select Syslog Servers and Click on Add

    Image
  3. Select theĀ Name or IP address of the Syslog server from the dropdown.

    Image
  4. SelectĀ Syslog FormatĀ as 'Enhanced'.
  5. Click ā€˜OK’.

Ā 

For testing, set upĀ packet capture based on syslog port UDP 514Ā and generate traffic based on the event type.

  1. Navigate toĀ Monitor|Tools &Ā  Monitor|Packet Monitor
  2. Navigate toĀ Advanced monitor filterĀ tab and enable all the check boxes
  3. Click on Save and start the packet capture

    Image

Ā 

Test Results snap:
Image

Ā 

  • Here, Source 192.168.x.x is the firewall generating the syslog traffic and forwarding it to the syslog server 192.168.x.x on UDP port 514.

Ā 

Resolution for SonicOS 6.5

This release includes significantĀ user interface changes and many new features that are different from the SonicOS 6.2 and earlier firmware. The below resolution is for customers using SonicOS 6.5 firmware.

Ā 

Configuration

  1. Login to the SonicWall firewall as admin.
  2. Navigate to Manage | Log Settings | SYSLOG .

    Image

  3. Under Syslog tab, Click on the AddĀ button.
    Image
  4. Ā Select the Name or IP address of the Syslog server from the dropdown.
  5. Select Syslog Format as 'Enhanced'.
  6. Click ā€˜OK’.
  7. After a couple of seconds, newly added Syslog server will show up.

    NOTE: To set syslog settings using templates, please follow:Ā 191018135555494.

    Ā 

Issue ID

SW5106

Related Articles

  • CSR generation and re-signing for expired DPI-SSL certificates for Gen7 firewalls on SonicOS 7.0.1, Gen6 and Gen6.5 running on firmware SonicOS 6.5.X.X
    Read More
  • SonicWall GEN8 TZs and GEN8 NSas Settings Migration
    Read More
  • What are dynamic external objects/groups and how can we configure it?
    Read More
not finding your answers?