Skip to main content

How to Integrate your SonicWall firewall

This guide will walk you through the process of configuring your SonicWall Firewall to log to Defense.com's SIEM platform.

Kara Crimson avatar
Written by Kara Crimson
Updated over a week ago

The SonicWall Firewall integration is available on our Enterprise and Advanced packages.

Before you get started

Before beginning the integration, you will need to deploy a log collector within the same network as your firewall.

To initiate the collector deployment process, please reach out to our Technical Support team, who'll provide you with a deployment pack that includes all the software and scripts needed to configure this.

If you already have a log collector deployed, please follow the steps outlined below.

Configuring your SonicWall firewall

  1. Access the SonicWall Management Interface.

    1. Open a web browser and navigate to the SonicWall firewall’s management IP address (e.g., https://192.168.1.1).

    2. Log in with administrative credentials.

  2. Configure Syslog Server Settings.

    1. Navigate to Manage > Log Settings > SYSLOG in the SonicWall interface (in older versions, this may be under Log > Syslog).

    2. In the Syslog Servers section, click Add.

    3. Configure the syslog server:

      • Name or IP Address: Enter the private IP address of your on-premise log collector.

    4. Port: 5514, which is the port the log collector is listening on (ensure this is set to 5514, not the default of 514).

    5. Server Type: Select Syslog.

    6. Protocol: Choose UDP.

      1. Click OK to save the syslog server configuration.

      2. Verify the syslog server appears in the Syslog Servers table.

  3. Set Syslog Format.

    1. In the Syslog Settings section, set the Syslog Format to Enhanced Syslog for richer log data (recommended for most modern syslog servers).

    2. Set the Syslog ID (default is firewall) to a unique identifier for your SonicWall device (e.g., NSAFirewall01) to help us distinguish the logs on our side.

    3. Click Apply to save changes.

Confirming log flow

Once the above steps are complete, your device will now ship logs to our SIEM platform via your collector. You can confirm logs are successfully reaching our SIEM by either.

  1. Navigating to the Log Search feature in Defense.com by browsing to SIEM > Log Search and then filtering the logs by type:"syslog".

  2. Reaching out to our Technical Support team, who'll be able to check and confirm this for you.

And that's it! You've successfully integrated your Sonicwall Firewall 🎉

Did this answer your question?