Skip to main content

How to integrate your Juniper switch

This guide will run you through how to get your Juniper switch logging to Defense.com's SIEM platform.

Alan Butcher avatar
Written by Alan Butcher
Updated this week

This integration is available on our Advanced and Enterprise packages.

Before you get started

Before beginning the integration, you will need to deploy a log collector within the same network as your switch.

To initiate the collector deployment process, please reach out to our Technical Support team, who'll provide you with a deployment pack that includes all the software and scripts needed to configure this.

If you already have a log collector deployed, please follow the steps outlined below.

Configuring syslog

  1. SSH or console into the switch

  2. Enter operational mode using the command cli

  3. Now, enter configuration mode using configure

  4. Set the syslog configuration using the following, replacing <LOG-COLLECTOR-IP> with the private IP address of your log collector

    set system syslog host <LOG-COLLECTOR-IP> any info
    set system syslog host <LOG-COLLECTOR-IP> port 5514
    set system syslog host <LOG-COLLECTOR-IP> facility local7
  5. Finally, commit the configuration changes with: commit

Configuration is not active until committed

Confirming log flow

Once the above steps are complete, your device will now ship logs to our SIEM platform via your collector. You can confirm logs are successfully reaching our SIEM by either.

  1. Navigating to the Log Search feature in Defense.com by browsing to SIEM > Log Search and then filtering the logs by type:"syslog".

  2. Reaching out to our Technical Support team, who'll be able to check and confirm this for you.

And that's it! You've successfully integrated your Juniper switch🎉

Did this answer your question?