NetXGATE NGFW
Integration Guide for NetXGATE NGFW with BluSapphire SIEM
Prerequisites
Confirm the following before starting configuration:
Requirement
Detail
NetXGATE Admin access
Administrator login to the NetXGATE NGFW management console. account
Network access
UDP port open from NetXGATE firewall to BluSapphire DataStreamer
Information needed
BluSapphire DataStreamer’s static private IP and UDP port number (to be shared by BluSapphire team)
Configuration Steps
Follow the steps below to add and configure the remote syslog server on the NetXGATE NGFW:
Step 1: Log in to the NetXGATE Firewall
1.
Open a browser and navigate to the NetXGATE NGFW management console URL.
2.
Enter your Administrator credentials and log in.
Step 2: Navigate to Remote Syslog Settings
1.
From the main menu, go to Configuration→ Management.
2.
Click on the Remote Syslog tab.
3.
A window labelled Remote Syslog Server will appear.
Step 3: Open the Configuration Editor
1.
Locate Rule ID-1 in the list.
2.
Check the checkbox next to Rule ID-1.
3.
Click Modify. The configuration editor will open.
Step 4: Enter Syslog Server Details
1.
Service: Enable the syslog service using the toggle.
2.
Description: Add a descriptive label for this syslog entry (e.g. BluSapphire SIEM).
3.
IP Address: Enter the BluSapphire DataStreamer’s static private IP.
4.
Port Number: Enter the UDP listener port shared by BluSapphire team.
5.
Protocol: Select UDP
Step 5: Configure Date Format, Hostname & Log Filters
1.
Date Format: Choose from YYYY-MM-DD, RFC3339, or Unix Timestamp.
2.
Hostname Format: Select Default Hostname.
3.
Log Filter Type: May be left as factory default.
Step 6: Select Log Format & Save
1.
In the Format field, select the syslog format. Currently the NetXGATE firewall produces logs in its standard Syslog format.
2.
Review all settings and confirm they match your syslog server configuration.
3.
Click Save to apply the configuration.
Troubleshooting
Symptom
Likely Cause
Fix
No logs arriving at syslog server
UDP/TCP blocked by intermediate firewall or ACL
Allow traffic on chosen port from the NetXGATE IP to DataStreamer IP
Last updated