The following content pack is available for use with a Graylog Illuminate license and Graylog Enterprise or Graylog Security. Contact sales to learn more about obtaining Illuminate.

SonicWall Next-Gen Firewalls (NGFW) include a range of products (NSsp, NSa, NSv, and TZ network security appliances) that provide application inspection, IDS/IPS, VPN, and traditional firewall functionality. This technology pack will process SonicWall NGFW event log messages, providing normalization, enrichment, and categorization of common events of interest.

Requirement(s)

  • SonicWall NGFW Device(s) running SonicOS version 6.5, 7.0, or later
  • Graylog Server with a valid Enterprise license, running Graylog version 4.2.5, 4.3.0, or later
  • SonicWall devices configured to send logs to Graylog via syslog
  • SonicWall devices configured to send enhanced syslog format

Stream Configuration

This technology pack includes one stream:

  • “Illuminate:SonicWall Device Messages”

Hint: If this stream does not exist prior to the activation of this pack, then it will be created and configured to route messages to this stream and the associated index set. There should not be any stream rules configured for this stream.

Index Set Configuration

This technology pack includes one index set definition:

  • “SonicWall Device Event Log Messages”
Warning: If this index set is already defined, then nothing will be changed. If this index set does not exist, then it will be created with default retention settings of a daily rotation and 90 days of retention, with 4 shards per index. It is strongly recommended to review and adjust these settings to best suit your environment.

Log Format Example

id=SDF2lk3rj sn=SD2342LJFS time="2022-04-22 11:02:41" fw=10.1.2.3 pri=4 c=1024 m=537 msg="Connection Closed" app=2 n=23593520 src=192.168.10.20:53323:IF0 dst=10.0.130.15:53:IF1 srcMac=00:15:5d:a1:a2:08 dstMac=f8:0f:6f:a8:a2:21 proto=udp/dns sent=85 rcvd=117 spkt=1 rpkt=1 cdur=30633 rule="3 (LAN->WAN)" fw_action="NA"

What Is Provided

  • Rules to normalize and enrich event log messages
  • A Spotlight content pack

Log Message Processing

Illuminate will identify SonicWall NGFW event log messages and add the field event_source_product with the value sonicwall_ngfw.

The Illuminate processing of SonicWall NGFW log messages provides the following:

  • Field extraction, normalization and message enrichment for SonicWall log messages
  • Graylog Schema compliance
  • GIM Categorization of the following messages:
SonicWall Event Code gim_event_category gim_event_subcategory gim_event_type
10 endpoint endpoint.service service error
22 detection detection.network detection network detection
23 detection detection.network detection network detection
24 authentication authentication.logoff session disconnect
25 detection detection.network detection network detection
27 detection detection.network detection network detection
28 detection detection.network detection network detection
31 authentication authentication.logon,authentication.credential validation logon
32 authentication authentication.logon,authentication.credential validation logon
33 authentication authentication.logon,authentication.credential validation logon
34 authentication authentication.credential validation error
81 detection detection.network detection network detection
82 detection detection.network detection network detection
83 detection detection.network detection network detection
139 authentication authentication.logon,authentication.credential validation logon
140 authentication authentication.logon,authentication.credential validation logon
141 authentication authentication.access notice error
150 endpoint endpoint.process process stopped
151 endpoint endpoint.process process stopped
177 detection detection.network detection network detection
178 detection detection.network detection network detection
179 detection detection.network detection network detection
229 detection detection.network detection network detection
237 authentication authentication.logon,authentication.credential validation logon
238 authentication authentication.logon,authentication.credential validation logon
243 authentication authentication.logon,authentication.credential validation logon
244 authentication authentication.logon,authentication.credential validation logon
245 authentication authentication.logon,authentication.credential validation logon
246 authentication authentication.logon,authentication.credential validation logon
248 detection detection.network detection network detection
267 detection detection.network detection network detection
328 iam iam.object modify account renamed
437 detection detection.network detection network detection
440 endpoint endpoint.service configuration change
441 endpoint endpoint.service configuration change
442 endpoint endpoint.service configuration change
446 detection detection.network detection network detection
486 authentication authentication.logon,authentication.credential validation logon
506 endpoint endpoint.service service stopped
508 endpoint endpoint.service service stopped
527 endpoint endpoint.ports port closed
528 endpoint endpoint.ports port closed
538 endpoint endpoint.ports port closed
546 detection detection.network detection network detection
548 detection detection.network detection network detection
549 authentication authentication.access policy device policy violation
560 iam iam.object disable account disabled
561 iam iam.object enable account enabled
564 authentication authentication.logoff session disconnect
580 detection detection.network detection network detection
583 detection detection.network detection network detection
606 detection detection.network detection network detection
608 detection detection.network detection network detection
609 detection detection.network detection network detection
656 authentication authentication.credential validation error
669 endpoint endpoint.service service error
676 endpoint endpoint.default endpoint message
677 endpoint endpoint.default endpoint message
682 endpoint endpoint.default endpoint message
701 endpoint endpoint.default endpoint message
728 endpoint endpoint.service service stopped
734 endpoint endpoint.default endpoint message
735 endpoint endpoint.default endpoint message
737 authentication authentication.credential validation error
744 authentication authentication.access notice error
745 authentication authentication.access notice error
746 authentication authentication.access notice error
747 authentication authentication.access notice error
748 authentication authentication.access notice error
749 authentication authentication.access notice error
750 authentication authentication.access notice error
751 authentication authentication.access notice error
752 authentication authentication.access notice error
753 authentication authentication.access notice error
754 authentication authentication.access notice error
755 authentication authentication.access notice error
756 authentication authentication.access notice error
757 authentication authentication.access notice error
758 authentication authentication.access notice error
759 authentication authentication.access notice error
789 detection detection.network detection network detection
790 detection detection.network detection network detection
793 detection detection.network detection network detection
794 detection detection.network detection network detection
795 detection detection.network detection network detection
809 detection detection.network detection network detection
864 detection detection.network detection network detection
866 detection detection.network detection network detection
868 detection detection.network detection network detection
879 detection detection.default detection message
881 endpoint endpoint.configuration system time changed
882 http,network http.communication,network.network connection network http communication
883 endpoint endpoint.default endpoint message
884 endpoint endpoint.default endpoint message
885 endpoint endpoint.default endpoint message
886 endpoint endpoint.default endpoint message
897 detection detection.network detection network detection
898 detection detection.network detection network detection
904 detection detection.default detection message
905 detection detection.default detection message
913 authentication authentication.credential validation error
987 authentication authentication.credential validation error
988 authentication authentication.access notice error
989 authentication authentication.access notice error
990 authentication authentication.access notice error
991 authentication authentication.access notice error
992 authentication authentication.default authentication message
993 authentication authentication.default authentication message
994 endpoint endpoint.service configuration change
995 endpoint endpoint.service configuration change
996 authentication authentication.default authentication message
997 authentication authentication.default authentication message
998 authentication authentication.default authentication message
999 endpoint endpoint.default endpoint message
1000 endpoint endpoint.default endpoint message
1001 endpoint endpoint.default endpoint message
1002 endpoint endpoint.default endpoint message
1003 endpoint endpoint.default endpoint message
1004 endpoint endpoint.default endpoint message
1005 endpoint endpoint.default endpoint message
1006 endpoint endpoint.default endpoint message
1011 iam iam.object modify password change
1033 authentication authentication.access notice error
1035 authentication authentication.logon,authentication.credential validation logon
1048 iam iam.object modify password change
1049 endpoint endpoint.filesystem file modified
1058 endpoint endpoint.process process altered
1059 endpoint endpoint.process process altered
1073 authentication authentication.access notice error
1075 authentication authentication.kerberos request error
1076 authentication authentication.default authentication message
1080 authentication authentication.logon,authentication.credential validation logon
1085 endpoint endpoint.service service stopped
1088 endpoint endpoint.service service error
1089 endpoint endpoint.service service error
1091 detection detection.network detection network detection
1092 detection detection.network detection network detection
1093 detection detection.network detection network detection
1117 authentication authentication.default authentication message
1118 authentication authentication.default authentication message
1119 authentication authentication.default authentication message
1120 authentication authentication.default authentication message
1121 authentication authentication.default authentication message
1122 authentication authentication.default authentication message
1123 authentication authentication.default authentication message
1157 iam iam.object disable account disabled
1158 iam iam.object disable account disabled
1180 detection detection.default detection message
1181 detection detection.default detection message
1190 iam iam.object modify group member added
1191 iam iam.object modify group member removed
1192 iam iam.object modify group member added
1193 iam iam.object modify group member removed
1198 detection detection.default detection message
1199 detection detection.default detection message
1200 detection detection.default detection message
1201 detection detection.default detection message
1202 authentication authentication.default authentication message
1203 authentication authentication.default authentication message
1204 authentication authentication.default authentication message
1209 detection detection.default detection message
1210 detection detection.default detection message
1211 detection detection.default detection message
1212 detection detection.default detection message
1213 detection detection.default detection message
1214 detection detection.default detection message
1226 http,network http.communication,network.network connection network http communication
1227 authentication authentication.access policy account policy violation
1229 network network.default network message
1231 endpoint endpoint.configuration system time changed
1243 authentication authentication.credential validation error
1316 detection detection.default detection message
1336 endpoint endpoint.service configuration change
1337 iam iam.object modify password change
1338 iam iam.object modify password change
1341 authentication authentication.default authentication message
1342 authentication authentication.default authentication message
1363 detection detection.default detection message
1366 detection detection.default detection message
1367 detection detection.default detection message
1369 detection detection.network detection network detection
1373 detection detection.network detection network detection
1374 detection detection.network detection network detection
1375 detection detection.network detection network detection
1376 detection detection.network detection network detection
1378 detection detection.default detection message
1382 endpoint endpoint.audit audit policy changed
1383 endpoint endpoint.audit audit error
1387 detection detection.network detection network detection
1393 endpoint endpoint.service service stopped
1432 endpoint endpoint.service configuration change
1438 endpoint endpoint.configuration system configuration modified
1439 endpoint endpoint.configuration system configuration modified
1440 endpoint endpoint.configuration system configuration modified
1441 endpoint endpoint.configuration system configuration modified
1450 detection detection.default detection message
1471 detection detection.default detection message
1490 http,network http.communication,network.network connection network http communication
1491 http,network http.communication,network.network connection network http communication
1517 authentication authentication.credential validation error
1518 detection detection.default detection message
1519 detection detection.default detection message
1522 endpoint endpoint.default endpoint message
1524 endpoint endpoint.default endpoint message
1525 endpoint endpoint.default endpoint message
1526 endpoint endpoint.default endpoint message
1552 authentication authentication.credential validation error
1553 authentication authentication.credential validation error
1554 authentication authentication.credential validation error
1555 authentication authentication.credential validation error
1556 authentication authentication.credential validation error
1557 authentication authentication.credential validation error
1572 authentication authentication.logon,authentication.credential validation logon
1585 authentication authentication.logon,authentication.credential validation logon
1590 endpoint endpoint.configuration system configuration modified
1595 endpoint endpoint.default endpoint message
1596 endpoint endpoint.default endpoint message
1599 endpoint endpoint.configuration system configuration modified
1600 endpoint endpoint.configuration system configuration modified
1601 endpoint endpoint.configuration system configuration modified
1627 iam iam.object disable account disabled
1632 endpoint endpoint.service service stopped
1634 endpoint endpoint.service service removed
1635 endpoint endpoint.service service error
1636 endpoint endpoint.default endpoint message
1637 endpoint endpoint.default endpoint message
1640 endpoint endpoint.service configuration change
1642 endpoint endpoint.ports port closed
1655 authentication authentication.access policy account policy violation
1674 endpoint endpoint.audit audit policy changed
Events associated with the built-in Administrative account

SonicWall NGFW devices are configured with a built-in Administrator account. The default name for this account is "Admin", but this can be altered by the user. Some events are logged by the SonicWall devices related to this account, which do not include the actual user name but instead just refer to "Administrator". Illuminate will assign a user_name value of "Administrator" for these events.

Severity Mapping

SonicWall devices have different severity level assignments which are mapped to the Graylog schema severity levels, in the fields event_severity and event_severity_level.

vendor_event_severity_severity vendor_event_severity event_severity_level event_severity
0 Emergency 5 critical
1 Alert 5 critical
2 Critical 5 critical
3 Error 4 high
4 Warning 3 medium
5 Notice 2 low
6 Info 1 informational
7 Debug 1 informational

Spotlight Content Pack

The Spotlight content pack contains:

  • Dashboard: Illuminate:SonicWall NGFW Overview

    • Overview tab: Summary of SonicWall device operations.

    • Alerts tab: Summary of SonicWall GIM categorized alerts

    • Network tab: Summary of Network Traffic


    • VPN tab: Summary of VPN activity


  • Saved Search: Illuminate:SonicWall NGFW Alert Log Viewer

    • View SonicWall NGFW GIM categorized Security Alerts
  • Saved Search: Illuminate:SonicWall NGFW Log Viewer - Filtered

    • Filter SonicWall NGFW logs by vendor severity, from the most critical level (0 - Emergency) to the least (7 - debug)
  • Saved Search: Illuminate:SonicWall NGFW Log Viewer

    • Saved search to view SonicWall NGFW Event Log Messages
  • Saved Search: Illuminate:SonicWall NGFW VPN Log Viewer

    • Saved search to view SonicWall NGFW VPN, SSL VPN, L2TP, and Portal Messages