Exporting Logs to ArcSight Logger
Configure ArcSight Logger
- Download ArcSight Logger from the HP website.
- Configure ArcSight Logger using the HP ArcSight Logger Admin Guide.
Configure the Barracuda Web Application Firewall
- Log into the Barracuda Web Application Firewall web interface.
- Go to ADVANCED > Export Logs.
- In the Syslog section, click Add Syslog Server and specify the following:
- Name - Enter a name for the syslog server.
- IP Address – Enter the IP address of the configured ArcSight Logger.
- Port – Enter the port number on which the logger listens.
- Connection Type – Set the connection type to transmit logs from the Barracuda Web Application Firewall to the syslog server.
- Specify values for other parameters as required and click Add.
- In the Logs Format section:
- Set ArcSight Log Header to Syslog Header.
- Set Web Firewall Logs, Access Logs and Audit Logs to CEF:0 (ArcSight) log format.
- Click Save.
- Send logs to the configured syslog server.
- Verify the ArcSight Logger displays the logs.
Exporting Logs to ArcSight SmartConnector
Configure SmartConnector
- Download the latest version of ArcSight SmartConnector from the HP website.
- Install ArcSight SmartConnector on Windows, Linux, or another supported platform by following the steps in the Smart Connector admin guide.
- Ensure SmartConnector listens on the UDP/TCP port, and that the port is connected to a logger or other device where the logs can be forwarded.
Configure the Barracuda Web Application Firewall
- Log into the Barracuda Web Application Firewall web interface.
- Go to ADVANCED > Export Logs.
- In the Syslog section, click Add Syslog Server and specify the following:
- Name - Enter a name for the syslog server.
- IP Address – Enter the IP address of the configured ArcSight SmartConnector.
- Port – Enter the port number on which the SmartConnector listens.
- Connection Type – Set the connection type to transmit the logs from the Barracuda Web Application Firewall to the syslog server.
- Specify values for other parameters as required and click Add.
- In the Logs Format section:
- Set ArcSight Log Header to Syslog Header.
- Set Web Firewall Logs, Access Logs and Audit Logs to CEF:0 (ArcSight) log format.
- Click Save.
- Send logs to the configured syslog server.
- Verify that the ArcSight Logger, or system where the SmartConnector forwards the logs, displays the logs.
The image below shows the configuration: