SonicWall NGFW Content Pack

The following content pack is available for use with a Graylog Illuminate license and Graylog Enterprise or Graylog Security. Contact sales to learn more about obtaining Illuminate.

SonicWall Next-Generation Firewall (NGFW) provides advanced threat protection, network security, and application control for enterprise environments. This content pack supports NSsp, NSa, NSv, and TZ series appliances running SonicOS 6.5, 7.0, or later. The pack processes SonicWall enhanced syslog messages, providing normalization, enrichment, and GIM categorization across network traffic, VPN, authentication, security services, and system administration events.

Requirements

  • SonicWall NGFW device(s) running SonicOS version 6.5, 7.0, or later

  • SonicWall configured to transmit syslog in enhanced format to your Graylog server

  • Graylog Server with a valid Enterprise license

Supported Versions

  • SonicOS 6.5.x

  • SonicOS 7.0.x and later

  • SonicWall NSsp, NSa, NSv, and TZ series appliances

Log Collection and Delivery

Configure your SonicWall device to send syslog messages to your Graylog server using the enhanced syslog format. The pack identifies SonicWall messages by matching key-value patterns (id=, sn=, time=, fw=) in the message content.

SonicWall Syslog Configuration

In the SonicWall management interface, navigate to Log > Syslog and configure:

  1. Set the syslog server IP to your Graylog server address

  2. Set the syslog port to match your Graylog Syslog input (default: 514/UDP or 1514/TCP)

  3. Enable Enhanced Syslog format for full field extraction

  4. Select the event categories to forward (recommended: all categories for complete visibility)

Stream Configuration

This technology pack includes 1 stream:

  • "Illuminate:SonicWall Device Messages"

Hint: If this stream does not exist prior to the activation of this pack then it will be created and configured to route messages to this stream and the associated index set. There should not be any stream rules configured for this stream.

Index Set Configuration

This technology pack includes 1 index set definition:

  • "SonicWall Device Event Log Messages"

Hint: If this index set is already defined, then nothing will be changed. If this index set does not exist, then it will be created with retention settings of a daily rotation and 90 days of retention. These settings can be adjusted as required after installation.

What is Provided

  • Parsing rules to extract SonicWall NGFW enhanced syslog into Graylog schema compatible fields

  • GIM event type categorization and enforcement fields for supported SonicWall NGFW events

  • SonicWall NGFW Spotlight dashboard with Overview, Alerts, Network, and VPN tabs

GIM Categorization

GIM categorization is provided for the following SonicWall event codes:

Fields Extracted by This Pack

Common Fields

Fields extracted from all SonicWall NGFW events.

SonicWall NGFW Spotlight Content Pack

The SonicWall NGFW Spotlight offers a dashboard with the following tabs:

Overview

Alerts

Network

VPN