WatchGuard Integration
Overview
WatchGuard Firebox appliances provide UTM security with integrated IPS, antivirus, and web filtering. KYRA MDR collects WatchGuard syslog data for comprehensive security monitoring. Supports Fireware OS 12.x.
Prerequisites
- A KYRA MDR Collector installed and running
- WatchGuard Firebox with administrative access
- WatchGuard System Manager or Web UI access
- Network connectivity from the Firebox to the collector on port 514
Configuration
Configure syslog in WatchGuard Web UI:
- Navigate to System > Logging
- Click Add under Syslog Servers
- Configure:
| Setting | Value |
|---|---|
| IP Address | Your KYRA Collector IP |
| Port | 514 |
| Log Format | Syslog |
| Log Level | Information |
- Under Log Settings, enable:
- Traffic logs (sent and denied)
- Alarm logs
- Event logs
- Save the configuration
Fireware Web UI Detailed Steps
The full configuration path in Fireware Web UI:
- Log in to the Firebox Web UI (
https://<firebox-ip>:8080) - Navigate to System > Logging
- In the Syslog Server section, click Add
- Enter the KYRA Collector IP address and port 514
- Set Log Level to Information (captures all security events)
- Click Save
- Under Logging > Log Settings, ensure these are checked:
- Send log messages when traffic is allowed
- Send log messages when traffic is denied
- Send alarm log messages
WatchGuard System Manager (WSM) CLI
# Via the Firebox CLI (Fireware CLI)# Connect via SSH or serial console
# Show current logging configurationshow logging
# Add a syslog serverset logging syslog-server <COLLECTOR_IP> port 514
# Enable traffic loggingset logging traffic-management sent-traffic enableset logging traffic-management denied-traffic enable
# Enable alarm loggingset logging alarm enable
# Save configurationsaveVerify Log Reception
# On the KYRA Collector, verify incoming WatchGuard logssudo tcpdump -i any port 514 -A | grep -i "watchguard\|Firebox\|fireware"
# Example WatchGuard syslog format# <134>1 2025-01-15T10:30:00+09:00 XTM-Firebox firewall: msg_id="3000-0148" Allow 192.168.1.100 10.0.0.1 443/tcp# <134>1 2025-01-15T10:30:01+09:00 XTM-Firebox firewall: msg_id="3000-0173" Deny 203.0.113.50 192.168.1.1 22/tcp
# Check rsyslog for WatchGuard eventstail -f /var/log/syslog | grep -i "firebox\|firewall"Collected Log Types
| Log Type | Description | Security Use |
|---|---|---|
| Traffic | Allowed and denied connections | Network monitoring, policy enforcement |
| Alarm | Security alerts and threshold events | Threat notification |
| IPS | Intrusion prevention events | Attack detection |
| GAV | Gateway antivirus detections | Malware blocking |
| WebBlocker | URL filtering events | Web security policy |
| APT Blocker | Advanced threat sandbox results | Zero-day detection |
Troubleshooting
Logs not arriving: WatchGuard uses UDP syslog by default. Verify network connectivity and that no upstream firewall blocks UDP 514.
Incomplete log data: Ensure all log types are enabled in the logging configuration. Traffic logs for allowed connections must be explicitly enabled.
Log format issues: WatchGuard uses a proprietary log format. KYRA MDR includes a dedicated WatchGuard parser.
Contact kyra@seekerslab.com for support.