Configure Juniper NetScreen Firewall Collection
Collecting Juniper NetScreen logs enables Alert Logic to run our common firewall analytics on data from your NetScreen firewall devices. These analytics identify suspicious communication with internet hosts which NetScreen considers threat actors. Significant security findings from your NetScreen devices will result in the creation of incidents that can be managed in the Alert Logic console.
You must complete the following to send data from your NetScreen device(s) to Alert Logic:
Download and install the remote collector
To send data from your NetScreen device(s) to Alert Logic, you must first download and install the remote collector in the same network as the NetScreen device(s).
To download and install the remote collector:
- Review the requirements for the remote collector as outlined in Requirements for the Alert Logic Remote Collector and ensure all requirements are met.
- Complete the following instructions for Linux or Windows, making sure to choose a host in the same network as the NetScreen device(s).
- While installing the remote collector, note the IP of the host where the collector is installed. This IP will be needed when configuring the NetScreen device.
Configure NetScreen device
Once the remote collector is installed, the NetScreen device needs to be configured to send data to the collector.
To configure the NetScreen device:
- Log into your NetScreen interface.
- Navigate to Configuration > Report Settings > Syslog.
- Select Enable Syslog Messages.
- Select Trust Interface as Source IP for VPN and Include Traffic Log.
- In the Syslog Host Name / Port field, type the IP address of the Alert Logic remote collector and port 1515.
- Click Apply to save the changes.
- Navigate to Configuration > Report Settings > WebTrends in the left pane of the NetScreen interface.
- Clear the Enable WebTrends Messages check box.
- Click Apply to save the changes.
Verify log collection
Once you have installed the remote collector and configured the NetScreen device, it is recommended to verify that log collection is successful. It may take up to 15 minutes for Alert Logic to begin receiving logs.
- Log in to the Alert Logic console and use one of the following links to access the Search console with criteria already entered:
- Uncomment either of the two commented lines with SQL parameters and replace either $COLLECTOR_ID or $COLLECTOR_IP with your preferred identifier for the remote collector.
- Click Search.
- Verify logs display for the remote collector.