This section describes how to send logs from Barracuda Web Application Firewall to Comm Broker using syslog.
The following logs can be segregated and distributed using the LOCAL 0 through LOCAL 7 facilities, making management of these logs on the external log servers easier.
System Logs: Logs events generated by the system showing the general activity of the system.
Web Firewall Logs: Logs events which indicate the web firewall activity such as allowing, blocking or modifying the incoming requests and responses as defined in the Barracuda Web Application Firewall rules and policies.
Access Logs: Logs events pertaining to traffic activity and various elements of the incoming HTTP request and the responses from the back-end servers.
Audit Logs: Logs events pertaining to the auditing events generated by the system including configuration and UI activity by users like admin.
Network Firewall Logs: Logs events generated whenever network traffic passing through the interfaces (WAN, LAN and MGMT) matches the configured Network ACL rule.
Barracuda Web Application Firewall version 7.0.x
Go to the ADVANCED > Export Logs page.
In the Export Logs section, click Add Export Log Server. The Add Export Log Server window appears.
Enter values for the following fields:
Name—Enter a name for the syslog NG server (your FireEye Comm Broker Sender).
Log Server Type—Select Syslog NG.
IP Address or Hostname—Enter the IP address or the hostname of the syslog NG server (your Trellix Comm Broker Sender).
Port—Enter the port associated with the IP address of the syslog NG server.
Connection Type—Select the connection type to transmit the logs from the Barracuda Web Application Firewall to the syslog server. UDP is the default port for syslog communication. UDP, TCP or SSL can be used with the NG Syslog server.
Validate Server Certificate—Select Yes to validate the syslog server certificate using the internal bundle of Certificate Authority (CAs) certificates packaged with the system. If you select No, any certificate from the syslog server is accepted.
Client Certificate—Select Yes to enable the Barracuda Web Application Firewall to present the certificate while connecting to the syslog server.
Certificate—Select a certificate for the Barracuda Web Application Firewall to present when connecting to the syslog server. (Upload certificates on the BASIC > Certificates page.)
Log Timestamp and Hostname—Select Yes to log the date and time of the event, and enter the hostname configured on the BASIC > IP Configuration > Domain Configuration section.
Click Add.