WatchGuard Firebox Firewall Data in Graylog

WatchGuard Data In Graylog

If you’re running WatchGuard Firebox appliances to protect your network, you already know how much is recorded in their logs: every allowed and denied connection, every user logon, every IPS and gateway antivirus detection, and every configuration change. Graylog provides a purpose-built way to make that signal immediately actionable. The WatchGuard Firebox Content Pack, available with an Illuminate license and Graylog Enterprise or Graylog Security, delivers ready-to-use parsing rules, streams, GIM categorization, a dashboard, and saved searches so you can turn raw Firebox syslog into structured, searchable security intelligence.

 

What is WatchGuard Firebox?

WatchGuard Firebox is a unified security platform that combines traditional traffic protection with defenses against intrusions, phishing attempts, malware, ransomware, and more. Fireboxes run the Fireware operating system and are available as both hardware and virtual appliances, bringing stateful firewalling, proxies, intrusion prevention, gateway antivirus, VPN, and user authentication together in one device.

Because the Firebox enforces policy at the boundary between your network zones and the internet, its logs capture who connected, what was allowed or denied, which threats were detected, and how the device itself was changed. Getting that data into Graylog in a normalized, correlated form is what turns a stream of raw Fireware syslog into usable detection and investigation data.

 

What This Pack Does

The WatchGuard Firebox Content Pack is purpose-built for Fireware 12.x and later. Once installed, it automatically parses Firebox event log messages into Graylog schema-compatible fields, enriches them, and maps them to the Graylog Information Model (GIM) using Fireware message IDs.

Included in the pack:

  • Stream: Illuminate:WatchGuard Device Messages, created automatically if it doesn’t exist, with routing preconfigured and no stream rules required.
  • Index Set: WatchGuard Device Logs, pre-defined with a daily rotation and 90-day retention, adjustable after installation.
  • Parsing Rules: Extracts WatchGuard Firebox logs into Graylog schema-compatible fields.
  • GIM Categorization: Event type categorization and enforcement fields for authentication, network traffic, proxy, detection, audit, signature update, DHCP, and operational events.
  • Spotlight: A dashboard and saved searches for Firebox activity.

 

Requirements

  • Graylog 4.2.5, 4.3.0, or later with a valid Enterprise or Security license and Illuminate installed
  • WatchGuard Firebox running Fireware 12.x or later
  • Firebox configured to send logs via syslog to a Graylog syslog input

 

Getting Logs into Graylog

Step 1 — Configure a Graylog Syslog Input

Create a local Syslog input on the Graylog server. The port you choose must match the port configured on the Firebox in the next step.

Step 2 — Configure Syslog in the Fireware Web UI

Configure the Firebox to send logs to Graylog:

  1. Select System > Logging.
  2. Click the Syslog Server
  3. Select Send log messages to these syslog servers.
  4. Click Add, then enter the Graylog server IP address.
  5. Configure the port to match the Graylog Syslog input.
  6. Select Syslog
  7. Select the timestamp and serial number boxes.
  8. Select a syslog facility (Local0 to Local7), and set Alarm to Local0 for high priority.
  9. Click Save.

Including the serial number in each message lets you tell individual Fireboxes apart when several devices send to the same input.

Step 3 — Install and Activate the Content Pack

In Graylog, navigate to Enterprise → Illuminate, locate the WatchGuard Firebox Processing Pack and Spotlight, and activate them. The stream and index set are created automatically. No additional rules are needed.

 

WatchGuard Firebox Log Message Processing

Every Fireware log message carries a msg_id that identifies the exact event type, and the pack uses these IDs to drive GIM categorization. Key elements extracted include:

  • Device context: the Firebox name, serial number, and timestamp from the message header, plus the process that generated the event (such as firewall).
  • Message ID: the Fireware msg_id, which maps each event to its GIM category and event type.
  • Traffic details: the disposition (Allow or Deny), source and destination interfaces, protocol, source and destination IPs and ports, and TCP details.
  • Geolocation: source and destination country from geo_src and geo_dst.
  • Policy: the name of the Firebox policy that handled the traffic.

 

Here is an example of an allowed inbound connection:

DEV01 0011223344556 (2022-09-01T13:58:33) firewall: msg_id=”3000-0148″

Allow External Inside 44 tcp 20 238 10.11.12.13 192.168.1.10 58325 60951

offset 6 S 3172487743 win 4 geo_src=”USA” geo_dst=”USA”

(Inbound Policy-00)

 

Events Processed by This Pack

The content pack processes a broad range of Firebox event types, including:

  • Authentication events: user authentication success and failure, logins, and logouts.
  • Firewall traffic: allowed and denied connections, policy alarms, blocked sites and ports, and spoofing events.
  • Proxy events: HTTP, HTTPS, and TCP-UDP proxy activity.
  • Detection events: IPS, gateway antivirus (GAV), and APT detections in proxies, plus flood, scan, DDoS, and spoofing attack events.
  • VPN events: VPN tunnel establishment.
  • Audit and maintenance: device configuration changes, signature updates, and signature version checks.
  • DHCP events: discover, offer, request, and acknowledgement messages.
  • Operational events: address, server status, connection, interface, and host blocking events.

 

GIM Categorization

WatchGuard Firebox events are mapped to the Graylog Information Model, enabling consistent correlation with other data sources across your environment:

Event Event IDs GIM Code GIM Category GIM Subcategory
User authentication succeeded/failed 1100-0004, 1100-0005 100000 authentication authentication.logon
User login succeeded 3E00-0002 100000 authentication authentication.logon
User logout 3E00-0004 102500 authentication authentication.logoff
Firewall traffic (allow/deny) 3000-0148, 3000-0149, 3000-0150, 3000-0173 120000 network network.network connection
Policy alarm, blocked site/port, spoofing 3000-0167, 3000-0168, 3000-0169, 3000-0172 120000 network network.network connection
VPN tunnel established 0207-0001 120000 network network.network connection
HTTP/HTTPS/TCP-UDP proxy events 1AFF-*, 2CFF-*, 2DFF-* 120000 network network.network connection
Operational events (address, server status, connections, interface, host blocking) 3000-0029/002A/003C/0040/00CB/012D/0170/0171, 3001-1001/1002, 3100-0030 219999 service service.default
Device configuration change 0101-0001 220500 audit audit.policy
Signature update 2E02-0065, 2E02-0066, 2E02-0067 280100 agent agent.update
Signature version check 2E02-0069 280200 agent agent.status
DHCP request 1600-0003, DHCPREQUEST 290000 dhcp dhcp.request
DHCP offer 1600-0002, DHCPOFFER 290100 dhcp dhcp.offer
DHCP discovery 1600-0001, DHCPDISCOVER 290200 dhcp dhcp.discovery
DHCP acknowledgement DHCPACK 290300 dhcp dhcp.acknowledgement
IPS/GAV/APT detection in proxy 1AFF-0025/0026/0028/0029/0034, 2CFF-0005, 2DFF-0001 300000 detection detection.network_detection
Attack events (flood, scan, DDoS, spoofing) 3000-0152 through 3000-0166 300000 detection detection.network_detection

 

Why Log WatchGuard Firebox Events?

Collecting Firebox logs gives you more than a record of network traffic. It directly supports security detection, incident response, and compliance audit use cases at the network perimeter.

Security Monitoring

  • Surface IPS, gateway antivirus, and APT detections as network detections in real time
  • Detect flood, scan, DDoS, and spoofing attacks against your perimeter
  • Monitor failed user authentication attempts for signs of password guessing
  • Track configuration changes to catch unauthorized or accidental policy modifications

Threat Hunting

  • Pivot from a detection’s source IP to every allowed connection from the same address
  • Use source and destination geolocation to find traffic to or from unexpected countries
  • Review proxy events for connections to suspicious destinations
  • Correlate VPN tunnel activity and user logons with your identity provider’s authentication logs

Incident Response

  • Reconstruct a host’s activity across traffic, proxy, and detection events on a single timeline
  • Identify which Firebox policy allowed or denied traffic during an incident
  • Use DHCP events to tie an IP address back to the device that held it at the time
  • Scope an incident across multiple Fireboxes using the device name and serial number

Compliance & Audit

  • Maintain a durable, searchable record of firewall enforcement, user access, and configuration changes
  • Demonstrate that security signatures are kept current using update and version check events
  • Support network security monitoring controls required by frameworks such as PCI DSS, HIPAA, ISO 27001, and SOC 2

WatchGuard-Overview 1

WatchGuard-Overview 2

 

Graylog Enterprise and Security

With Graylog Enterprise and Security, your team gains structured visibility into the perimeter enforced by your WatchGuard Fireboxes. The WatchGuard Firebox Content Pack turns raw Fireware syslog into searchable, correlated, GIM-tagged data that flows directly into your threat detection, alerting, and investigation workflows. For more on this integration, please follow the documentation.

Categories

Get the Monthly Tech Blog Roundup

Subscribe to the latest in log management, security, and all things Graylog blog delivered to your inbox once a month.