Wazuh + Sonicwall

25 views
Skip to first unread message

Brenno Garcia

unread,
Dec 4, 2025, 4:16:11 PM (2 days ago) Dec 4
to Wazuh | Mailing List
Hello,

I need help configuring Wazuh to handle logs and alerts from SonicWall.

I've already configured the syslog server on the SonicWall to forward logs to Wazuh.

Wazuh is receiving these logs, and that part is correct.

The problem is that SonicWall is only sending network logs (gcat=6, according to the documentation), and I can't configure it to send other types of logs.

I've searched some documentation, but none mention this part.

I edited all the logs on SonicWall to be sent to event profile 1 (Wazuh server configuration in Syslog), but it still didn't work.

Javier Adán Méndez Méndez

unread,
Dec 5, 2025, 12:40:27 AM (2 days ago) Dec 5
to Wazuh | Mailing List

Hi Brenno Garcia

Wazuh is already receiving SonicWall logs, so the syslog collector is working correctly on our side.
If only gcat=6 events are arriving, that means SonicWall is only forwarding that category. Wazuh does not filter SonicWall log types, and it cannot request additional categories.

Still, here are a few quick checks you can do to confirm everything is fine on the Wazuh side:

  1. Verify syslog collection is enabled

<localfile> <log_format>syslog</log_format> <location>/var/ossec/logs/archives/logs</location> </localfile>
  1. If you're using direct syslog input

<localfile> <log_format>syslog</log_format> <protocol>udp</protocol> <port>514</port> </localfile>
  1. Confirm logs are arriving

sudo tcpdump -i any port 514 -A
  1. Check Wazuh manager logs

tail -f /var/ossec/logs/ossec.log

If Wazuh is already receiving events, then the remaining categories need to be enabled on the SonicWall side. Wazuh will ingest anything the device sends.

Feel free to share a few sample logs if you want us to confirm the format.

Regards,

Javier Mendez

Wazuh Teams

Brenno Garcia

unread,
Dec 5, 2025, 11:07:18 AM (2 days ago) Dec 5
to Wazuh | Mailing List
Is there a guide for this part in SonicWall?

All the guides I've found never show the part where we configure which logs will be sent.

Javier Adán Méndez Méndez

unread,
Dec 5, 2025, 1:19:59 PM (2 days ago) Dec 5
to Wazuh | Mailing List
Reply all
Reply to author
Forward
0 new messages