Skip to main content

Set up

  1. Follow the shared Log Forwarders guide to add Barracuda CloudGen Firewall and open Forwarder Details (or ask Chat for the listener ip:port)
  2. In Barracuda Firewall Admin, go to Configuration > Configuration Tree > Box > Infrastructure Services > Syslog Streaming and click Lock
  3. Under Basic Setup, set Enable Syslog Streaming to yes
  4. Under Logstream Destinations, add a destination with the IP and port from Forwarder Details. When the listener shows UDP/TCP, choose either TCP or UDP on the Barracuda destination. When it shows only one transport, use that one.
  5. Under Logdata Filters, add a filter that includes the Box and Service log files plus the firewall Activity, Audit, and Threat logs
  6. Under Logdata Streams, add a stream that sends the filter to the Wirespeed destination
  7. Click Send Changes and Activate
  8. Events will begin showing up shortly
Wirespeed parses firewall activity and audit sessions, IPS threat events, scan detections, and VPN and administrator logins into dedicated fields. All other box and service log lines are stored with their log file name and message.