Skip to content

WatchGuard Integration

Overview

WatchGuard Firebox appliances provide UTM security with integrated IPS, antivirus, and web filtering. KYRA MDR collects WatchGuard syslog data for comprehensive security monitoring. Supports Fireware OS 12.x.

Prerequisites

  • A KYRA MDR Collector installed and running
  • WatchGuard Firebox with administrative access
  • WatchGuard System Manager or Web UI access
  • Network connectivity from the Firebox to the collector on port 514

Configuration

Configure syslog in WatchGuard Web UI:

  1. Navigate to System > Logging
  2. Click Add under Syslog Servers
  3. Configure:
SettingValue
IP AddressYour KYRA Collector IP
Port514
Log FormatSyslog
Log LevelInformation
  1. Under Log Settings, enable:
    • Traffic logs (sent and denied)
    • Alarm logs
    • Event logs
  2. Save the configuration

Fireware Web UI Detailed Steps

The full configuration path in Fireware Web UI:

  1. Log in to the Firebox Web UI (https://<firebox-ip>:8080)
  2. Navigate to System > Logging
  3. In the Syslog Server section, click Add
  4. Enter the KYRA Collector IP address and port 514
  5. Set Log Level to Information (captures all security events)
  6. Click Save
  7. Under Logging > Log Settings, ensure these are checked:
    • Send log messages when traffic is allowed
    • Send log messages when traffic is denied
    • Send alarm log messages

WatchGuard System Manager (WSM) CLI

Terminal window
# Via the Firebox CLI (Fireware CLI)
# Connect via SSH or serial console
# Show current logging configuration
show logging
# Add a syslog server
set logging syslog-server <COLLECTOR_IP> port 514
# Enable traffic logging
set logging traffic-management sent-traffic enable
set logging traffic-management denied-traffic enable
# Enable alarm logging
set logging alarm enable
# Save configuration
save

Verify Log Reception

Terminal window
# On the KYRA Collector, verify incoming WatchGuard logs
sudo tcpdump -i any port 514 -A | grep -i "watchguard\|Firebox\|fireware"
# Example WatchGuard syslog format
# <134>1 2025-01-15T10:30:00+09:00 XTM-Firebox firewall: msg_id="3000-0148" Allow 192.168.1.100 10.0.0.1 443/tcp
# <134>1 2025-01-15T10:30:01+09:00 XTM-Firebox firewall: msg_id="3000-0173" Deny 203.0.113.50 192.168.1.1 22/tcp
# Check rsyslog for WatchGuard events
tail -f /var/log/syslog | grep -i "firebox\|firewall"

Collected Log Types

Log TypeDescriptionSecurity Use
TrafficAllowed and denied connectionsNetwork monitoring, policy enforcement
AlarmSecurity alerts and threshold eventsThreat notification
IPSIntrusion prevention eventsAttack detection
GAVGateway antivirus detectionsMalware blocking
WebBlockerURL filtering eventsWeb security policy
APT BlockerAdvanced threat sandbox resultsZero-day detection

Troubleshooting

Logs not arriving: WatchGuard uses UDP syslog by default. Verify network connectivity and that no upstream firewall blocks UDP 514.

Incomplete log data: Ensure all log types are enabled in the logging configuration. Traffic logs for allowed connections must be explicitly enabled.

Log format issues: WatchGuard uses a proprietary log format. KYRA MDR includes a dedicated WatchGuard parser.

Contact kyra@seekerslab.com for support.