Skip to content

Firewall Integration Input Consistency  #1878

@jamiehynds

Description

@jamiehynds

We currently support several firewall integrations including Cisco, Palo Alto, Check Point and more. However, there are inconsistencies across the ingest options, such as supported protocols and syslog format (UDP/TCP/TCP+TLS) and syslog format (RFC3164 vs RFC5424). We need to ensure each integration is consistent across protocols and syslog format supported. Given how popular the firewall Beats modules are, we should consider enhancement to the modules as part of this effort too.

Cisco ASA/FTD/IOS

  • UDP
  • TCP
  • TCP + TLS
  • RFC3164
  • RFC5424

Check Point

  • UDP
  • TCP
  • TCP + TLS
  • RFC3164
  • RFC5424

Fortinet

  • UDP
  • TCP
  • TCP + TLS
  • RFC3164
  • RFC5424

Juniper SRX

  • UDP
  • TCP
  • TCP + TLS
  • RFC3164
  • RFC5424

Palo Alto

Sophos XG

  • UDP
  • TCP
  • TCP + TLS
  • RFC3164
  • RFC5424

Metadata

Metadata

Type

No type
No fields configured for issues without a type.

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions