Blumira’s modern cloud SIEM platform integrates with SonicWall Next-Generation Firewall to stream security event logs to the Blumira service.
Additionally, enabling Blumira’s dynamic blocklist capabilities on your integrated next-generation firewall allows us to provide automated blocking of known threats. Learn more about enabling Blumira’s blocklists to block malicious source IP addresses and domains for automated threat response.
Before you begin
Determine the Blumira sensor you will use as a syslog server to collect log data. On the sensor detail screen, under Host Details, copy the IP address of your Blumira sensor to use when configuring SonicWall.
Configuring log forwarding
To begin forwarding logs to Blumira, follow these steps:
- Log in to the SonicWall device as an Admin.
- Navigate to Manage > Log Settings > SYSLOG.
- Click Add.
- In the Name or IP Address field, enter the IP address of the Blumira sensor.
- Click OK.
Note: If you are pushing syslogs to another source, you will need to prioritize the Blumira policy higher to push logs to Blumira.
An additional guide is available at Sonicwall.com.