Skip to main content
Many Wirespeed integrations accept logs from firewalls, network devices, and other sources through a forwarder. After you add the integration, Wirespeed prepares that forwarder and shows the connection details you need.

Set up a forwarder

  1. Login to Wirespeed and navigate to Integrations > Add Integration
  2. Select the integration for your vendor or log source and click Integrate
  3. Wirespeed prepares the forwarder after the integration is added
  4. When it is ready, open Forwarder Details on the integration page
  5. Copy the IP address or domain and the listener port(s) shown there
  6. Configure your vendor or source to send logs using those details
  7. Confirm logs appear in Events
Each integration page covers any vendor-specific steps, protocol choices, or formats.

Understanding the connection details

Forwarder Details shows an IP address or domain and one or more listener ports. Your devices send logs to that destination. The port identifies which Wirespeed integration the logs belong to, so they appear under the correct vendor in Events.

When do I need multiple forwarders?

Different vendors or services need separate integrations — and therefore separate forwarders. For example, a SonicWall firewall and a Cisco Meraki deployment each get their own connection details. Multiple devices of the same vendor can usually share one forwarder. Several FortiGate firewalls, for example, can all send to the same IP and port. Use device name, source IP, or other fields in the logs to tell appliances apart. If you want separate groups of the same vendor (for example, firewalls in different regions), add another integration of that type. Each integration gets its own forwarder and appears separately in Events.