跳至正文

Juniper SRX Integration

Overview

Juniper SRX Series firewalls provide advanced security services including IPS, UTM, and application visibility. KYRA MDR ingests Juniper structured syslog data for threat detection and compliance monitoring. Supports Junos OS 19.x and later.

Prerequisites

  • A KYRA MDR Collector installed and running
  • Juniper SRX with administrative CLI or J-Web access
  • Network connectivity from the SRX to the collector on port 514
  • Junos OS 19.1 or later

Configuration

Configure syslog forwarding on the Juniper SRX:

set system syslog host <collector-ip> any info
set system syslog host <collector-ip> port 514
set system syslog host <collector-ip> structured-data
set system syslog host <collector-ip> facility-override local7
set security log mode stream
set security log transport protocol tcp
set security log stream kyra-mdr host <collector-ip>
set security log stream kyra-mdr host port 514
set security log stream kyra-mdr format sd-syslog
commit

Verify configuration with show system syslog and show security log.

Collected Log Types

Log TypeDescriptionSecurity Use
SecurityFirewall policy match eventsAccess control monitoring
IDPIntrusion detection/prevention eventsAttack detection, exploit blocking
FlowSession creation and teardownNetwork flow visibility
ScreenDoS protection eventsFlood and scan detection
AppTrackApplication identification logsShadow IT discovery, app control
NATAddress translation eventsNetwork forensics

Troubleshooting

No structured logs: Ensure structured-data is enabled in the syslog configuration. KYRA MDR parses structured syslog (RFC 5424) for best results.

Missing security logs: Security logging requires stream mode. Verify set security log mode stream is configured.

Duplicate events: If both system syslog and security stream are configured to the same host, you may see duplicates. Use only the security stream for firewall events.

Contact kyra@seekerslab.com for support.