Barracuda WAF Syslog

This article describes the steps to configure Barracuda WAF Syslog with DNIF.

The following properties are specific to the Barracuda Networks WAF:

  • Collection method: Syslog
  • Format: Regex
  • Functionality: Web Application Firewall
Prerequisites

Before you connect Barracuda Networks WAF, obtain the IP address of the Remote Server and verify that firewalls between the Barracuda appliance and Remote Server allow UDP traffic on port 514.

References

Configuring the Barracuda Networks WAF connection:

OptionDescription
Web Firewall Logs FacilitySelect a syslog facility between Local0 and Local7.
Access Logs FacilitySelect a syslog facility between Local0 and Local7.
Audit Logs FacilitySelect a syslog facility between Local0 and Local7.
System Logs FacilitySelect a syslog facility between Local0 and Local7.
  1. Click Add Export Log Server in the Export Logs section. The Add Export Log Server window opens.
  2. Specify values for the following:
OptionDescription
NameThe name of the Remote Console or Event Collector
Syslog ServerThe IP address of your Remote Server or Event Collector.
PortThe port that is associated with the IP address of your Remote Server or Event Collector.
If syslog messages are sent by UDP, use the default port, 514.
Connection TypeThe connection type transmits the logs from the Barracuda Web Application Firewall to the Remote Server or Event Collector. UDP is the default protocol for syslog communication.
Validate Server CertificateNo
  1. Select Yes from the Log Unit Name option.
  2. Select the default format from the list box for the following log types in the Log Formats pane:
    • Web Firewall Logs Format
    • Access Logs Format
    • Audit Logs Format
    • Network Firewall Logs Format
    • System Logs Format
  3. Click Save Changes.
  4. Go to Menu > Basic > Administration.
  5. Click Restart from the System/Reload/Shutdown pane.
  6. Configuring Syslog Connector in DNIF:

NOTE: By Default, a Syslog Connector is already configured and present in the Data Source with listener port on 514, but if it is not present then only proceed with the below steps to configure a new syslog connector. 

  1. Go to System > Data Sources.
  2. Click ‘+’ icon in the top right corner to add a new data source.
  3. Select Syslog and then click Next.
  4. Provide a suitable name for the Syslog Connector.
  5. Provide the Listener port value as ‘514’.
  6. Click Next.