Skip to content

s0p4L1n3/Graylog_Content_Pack_Stormshield_Firewall

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

11 Commits
 
 
 
 
 
 

Repository files navigation

Stormshield Firewall Content Pack

Tested with Stormshield 4.0.3 and Graylog 6.0.2. Should work with all Stormshield 4.X version.

The Content Pack should be compatible with all Graylog 5.X and 6.X version.

Note this was built without extractors, only pipeline rules.

Includes

  • Input (Syslog/UDP/1514)
  • Stream (Firewall)
  • Pipeline Rule w/ 1 stage (Extract key/values pipeline function)
  • Dashboard (24h) (Stats Firewall)

Requirements

  • Graylog 5.0
  • Stormshield Firewall w/ Syslog 1514/UDP Ports
  • Open port 1514 for UDP on the graylog host and/or docker compose file
  • Edit content-pack.json and find the strings:
    • firewall.lab.lan and rename it according to your firewall hostname.
    • Europe/Paris and rename it according to your server Timezone
  • Make sure set order according to below image in System > Configuration > Message Processors image

Install the content pack

Install_content_pack

Stormshield Firewall Syslog configuration

image

Screenshots

image

image

About

Graylog_Content_Pack_Stormshield_Firewall

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published