Configure WatchGuard Firewall Collection
Collecting WatchGuard logs enables Alert Logic to run our common firewall analytics on data from your WatchGuard firewall devices. These analytics identify suspicious communication with internet hosts which WatchGuard considers threat actors. Significant security findings from your WatchGuard devices will result in the creation of incidents that can be managed in the Alert Logic console.
You must complete the following to send data from your WatchGuard device(s) to Alert Logic:
Download and install the remote collector
To send data from your WatchGuard device(s) to Alert Logic, you must first download and install the remote collector in the same network as the WatchGuard device(s).
To download and install the remote collector:
- Review the requirements for the remote collector as outlined in Requirements for the Alert Logic Remote Collector and ensure all requirements are met.
- Complete the following instructions for Linux or Windows, making sure to choose a host in the same network as the WatchGuard device(s).
- While installing the remote collector, note the IP of the host where the collector is installed. This IP will be needed when configuring the WatchGuard device.
Configure WatchGuard device
Once the remote collector is installed, the WatchGuard device needs to be configured to send data to the collector.
To configure the WatchGuard device:
- Log into your WatchGuard Policy Manager.
- Navigate to Setup > Logging. A dialog box will appear.
- Click Send log messages to this syslog server and complete the following fields:
- IP address: <the IP address of your Alert Logic remote collector>
- Port = 1515
- Log format = Syslog
- Click OK.
Verify log collection
Once you have installed the remote collector and configured the WatchGuard device, it is recommended to verify that log collection is successful. It may take up to 15 minutes for Alert Logic to begin receiving logs.
- Log in to the Alert Logic console and use one of the following links to access the Search console with criteria already entered:
- Uncomment either of the two commented lines with SQL parameters and replace either $COLLECTOR_ID or $COLLECTOR_IP with your preferred identifier for the remote collector.
- Click Search.
- Verify logs display for the remote collector.