For the complete documentation index, see llms.txt. This page is also available as Markdown.

NetXGATE NGFW

Integration Guide for NetXGATE NGFW with BluSapphire SIEM

Prerequisites

Confirm the following before starting configuration:

Requirement

Detail

NetXGATE Admin access

Administrator login to the NetXGATE NGFW management console. account

Network access

UDP port open from NetXGATE firewall to BluSapphire DataStreamer

Information needed

BluSapphire DataStreamer’s static private IP and UDP port number (to be shared by BluSapphire team)

Configuration Steps

Follow the steps below to add and configure the remote syslog server on the NetXGATE NGFW:

Step 1: Log in to the NetXGATE Firewall

1.

Open a browser and navigate to the NetXGATE NGFW management console URL.

2.

Enter your Administrator credentials and log in.

Step 2: Navigate to Remote Syslog Settings

1.

From the main menu, go to ConfigurationManagement.

2.

Click on the Remote Syslog tab.

3.

A window labelled Remote Syslog Server will appear.

Step 3: Open the Configuration Editor

1.

Locate Rule ID-1 in the list.

2.

Check the checkbox next to Rule ID-1.

3.

Click Modify. The configuration editor will open.

Step 4: Enter Syslog Server Details

1.

Service: Enable the syslog service using the toggle.

2.

Description: Add a descriptive label for this syslog entry (e.g. BluSapphire SIEM).

3.

IP Address: Enter the BluSapphire DataStreamer’s static private IP.

4.

Port Number: Enter the UDP listener port shared by BluSapphire team.

5.

Protocol: Select UDP

Step 5: Configure Date Format, Hostname & Log Filters

1.

Date Format: Choose from YYYY-MM-DD, RFC3339, or Unix Timestamp.

2.

Hostname Format: Select Default Hostname.

3.

Log Filter Type: May be left as factory default.

Step 6: Select Log Format & Save

1.

In the Format field, select the syslog format. Currently the NetXGATE firewall produces logs in its standard Syslog format.

2.

Review all settings and confirm they match your syslog server configuration.

3.

Click Save to apply the configuration.

Troubleshooting

Symptom

Likely Cause

Fix

No logs arriving at syslog server

UDP/TCP blocked by intermediate firewall or ACL

Allow traffic on chosen port from the NetXGATE IP to DataStreamer IP

Last updated