> For the complete documentation index, see [llms.txt](https://docs.blusapphire.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.blusapphire.io/log-forwarding/03_log-forwarding-guide/log-forward/netxgate-ngfw.md).

# NetXGATE NGFW

Integration Guide for **NetXGATE NGFW** with **BluSapphire SIEM**

**Prerequisites**

Confirm the following before starting configuration:

<table data-header-hidden><thead><tr><th width="258.53515625"></th><th></th></tr></thead><tbody><tr><td><strong>Requirement</strong></td><td><strong>Detail</strong></td></tr><tr><td><strong>NetXGATE Admin access</strong></td><td>Administrator login to the NetXGATE NGFW management console. account</td></tr><tr><td><strong>Network access</strong></td><td>UDP port open from NetXGATE firewall to BluSapphire DataStreamer</td></tr><tr><td><strong>Information needed</strong></td><td>BluSapphire DataStreamer’s static private IP and UDP port number (to be shared by BluSapphire team)</td></tr></tbody></table>

**Configuration Steps**

Follow the steps below to add and configure the remote syslog server on the NetXGATE NGFW:

**Step 1: Log in to the NetXGATE Firewall**

<table data-header-hidden><thead><tr><th width="79.26171875"></th><th></th></tr></thead><tbody><tr><td><strong>1.</strong></td><td>Open a browser and navigate to the NetXGATE NGFW management console URL.</td></tr><tr><td><strong>2.</strong></td><td>Enter your Administrator credentials and log in.</td></tr></tbody></table>

**Step 2: Navigate to Remote Syslog Settings**

<table data-header-hidden><thead><tr><th width="81.0390625"></th><th></th></tr></thead><tbody><tr><td><strong>1.</strong></td><td>From the main menu, go to <strong>Configuration</strong>→ <strong>Management</strong>.</td></tr><tr><td><strong>2.</strong></td><td>Click on the <strong>Remote Syslog</strong> tab.</td></tr><tr><td><strong>3.</strong></td><td>A window labelled Remote Syslog Server will appear.</td></tr></tbody></table>

**Step 3: Open the Configuration Editor**

<table data-header-hidden><thead><tr><th width="78.9375"></th><th></th></tr></thead><tbody><tr><td><strong>1.</strong></td><td>Locate Rule ID-1 in the list.</td></tr><tr><td><strong>2.</strong></td><td>Check the checkbox next to Rule ID-1.</td></tr><tr><td><strong>3.</strong></td><td>Click Modify. The configuration editor will open.</td></tr></tbody></table>

**Step 4: Enter Syslog Server Details**

<table data-header-hidden><thead><tr><th width="78.9765625"></th><th></th></tr></thead><tbody><tr><td><strong>1.</strong></td><td><strong>Service:</strong> Enable the syslog service using the toggle.</td></tr><tr><td><strong>2.</strong></td><td><strong>Description:</strong> Add a descriptive label for this syslog entry (e.g. BluSapphire SIEM).</td></tr><tr><td><strong>3.</strong></td><td><strong>IP Address:</strong> Enter the BluSapphire DataStreamer’s static private IP.</td></tr><tr><td><strong>4.</strong></td><td><strong>Port Number:</strong> Enter the UDP listener port shared by BluSapphire team.</td></tr><tr><td><strong>5.</strong></td><td><strong>Protocol:</strong> Select UDP</td></tr></tbody></table>

**Step 5: Configure Date Format, Hostname & Log Filters**

<table data-header-hidden><thead><tr><th width="79.90234375"></th><th></th></tr></thead><tbody><tr><td><strong>1.</strong></td><td><strong>Date Format:</strong> Choose from YYYY-MM-DD, RFC3339, or Unix Timestamp.</td></tr><tr><td><strong>2.</strong></td><td><strong>Hostname Format:</strong> Select <strong>Default Hostname.</strong></td></tr><tr><td><strong>3.</strong></td><td><strong>Log Filter Type:</strong> May be left as factory default.</td></tr></tbody></table>

**Step 6: Select Log Format & Save**

<table data-header-hidden><thead><tr><th width="94.5859375"></th><th></th></tr></thead><tbody><tr><td><strong>1.</strong></td><td>In the Format field, select the syslog format. Currently the NetXGATE firewall produces logs in its standard Syslog format.</td></tr><tr><td><strong>2.</strong></td><td>Review all settings and confirm they match your syslog server configuration.</td></tr><tr><td><strong>3.</strong></td><td>Click Save to apply the configuration.</td></tr></tbody></table>

**Troubleshooting**

| **Symptom**                       | **Likely Cause**                                | **Fix**                                                              |
| --------------------------------- | ----------------------------------------------- | -------------------------------------------------------------------- |
| No logs arriving at syslog server | UDP/TCP blocked by intermediate firewall or ACL | Allow traffic on chosen port from the NetXGATE IP to DataStreamer IP |
