How to Export Logs to ArcSight SIEM Devices
Exporting Logs to ArcSight Logger
Download ArcSight Logger from the HP website.
Configure ArcSight Logger using the HP ArcSight Logger Admin Guide.
Configure the Barracuda Web Application Firewall
Log into the Barracuda Web Application Firewall web interface.
Go to ADVANCED > Export Logs.
In the Syslog section, click Add Syslog Server and specify the following:
Name - Enter a name for the syslog server.
IP Address – Enter the IP address of the configured ArcSight Logger.
Port – Enter the port number on which the logger listens.
Connection Type – Set the connection type to transmit logs from the Barracuda Web Application Firewall to the syslog server.
Specify values for other parameters as required and click Add.
In the Logs Format section:
Set ArcSight Log Header to Syslog Header.
Set Web Firewall Logs, Access Logs and Audit Logs to CEF:0 (ArcSight) log format.
Click Save.
Send logs to the configured syslog server.
Verify the ArcSight Logger displays the logs.
Exporting Logs to ArcSight SmartConnector
Download the latest version of ArcSight SmartConnector from the HP website.
Install ArcSight SmartConnector on Windows, Linux, or another supported platform by following the steps in the Smart Connector admin guide.
Ensure SmartConnector listens on the UDP/TCP port, and that the port is connected to a logger or other device where the logs can be forwarded.
Configure the Barracuda Web Application Firewall
Log into the Barracuda Web Application Firewall web interface.
Go to ADVANCED > Export Logs.
In the Syslog section, click Add Syslog Server and specify the following:
Name - Enter a name for the syslog server.
IP Address – Enter the IP address of the configured ArcSight SmartConnector.
Port – Enter the port number on which the SmartConnector listens.
Connection Type – Set the connection type to transmit the logs from the Barracuda Web Application Firewall to the syslog server.
Specify values for other parameters as required and click Add.
In the Logs Format section:
Set ArcSight Log Header to Syslog Header.
Set Web Firewall Logs, Access Logs and Audit Logs to CEF:0 (ArcSight) log format.
Click Save.
Send logs to the configured syslog server.
Verify that the ArcSight Logger, or system where the SmartConnector forwards the logs, displays the logs.
The image below shows the configuration:
Contact Us
Barracuda Campus
Barracuda Support