Juniper SRX Integration
Overview
Juniper SRX Series firewalls provide advanced security services including IPS, UTM, and application visibility. KYRA MDR ingests Juniper structured syslog data for threat detection and compliance monitoring. Supports Junos OS 19.x and later.
Prerequisites
- A KYRA MDR Collector installed and running
- Juniper SRX with administrative CLI or J-Web access
- Network connectivity from the SRX to the collector on port 514
- Junos OS 19.1 or later
Configuration
Configure syslog forwarding on the Juniper SRX:
set system syslog host <collector-ip> any infoset system syslog host <collector-ip> port 514set system syslog host <collector-ip> structured-dataset system syslog host <collector-ip> facility-override local7set security log mode streamset security log transport protocol tcpset security log stream kyra-mdr host <collector-ip>set security log stream kyra-mdr host port 514set security log stream kyra-mdr format sd-syslogcommitVerify configuration with show system syslog and show security log.
Collected Log Types
| Log Type | Description | Security Use |
|---|---|---|
| Security | Firewall policy match events | Access control monitoring |
| IDP | Intrusion detection/prevention events | Attack detection, exploit blocking |
| Flow | Session creation and teardown | Network flow visibility |
| Screen | DoS protection events | Flood and scan detection |
| AppTrack | Application identification logs | Shadow IT discovery, app control |
| NAT | Address translation events | Network forensics |
Troubleshooting
No structured logs: Ensure structured-data is enabled in the syslog configuration. KYRA MDR parses structured syslog (RFC 5424) for best results.
Missing security logs: Security logging requires stream mode. Verify set security log mode stream is configured.
Duplicate events: If both system syslog and security stream are configured to the same host, you may see duplicates. Use only the security stream for firewall events.
Contact kyra@seekerslab.com for support.