Requirements
A Huawei USG Firewall device.
Have admin access to create a new Forwarding configuration.
Have the most recent version of the Lumu Virtual Appliance installed.
These are the general steps you should follow to configure a syslog server on Huawei USG Firewall to send all metadata to Lumu:
Deploy and Set Up Lumu VA
All the detailed steps and guidance to create, download and install a virtual appliance on your preferred hypervisor or Cloud solution are available in our documentation:
- Deploy Virtual Appliances
- Configure Virtual Appliances and setup collectors
Set up a Lumu VA Firewall Log Collector
Go to the Lumu Virtual Appliance and refresh the VA Collectors settings by running the command lumu-appliance collectors refresh. If the appliance is running, it must be stopped in order to continue the setup process.
Select the option that refers to Huawei Firewall, then input the following data:
Protocol type: Select the UDP option. Huawei Firewall uses UDP protocol to send Syslog data.
Port number: Provide a number between 1024 and 65535, inclusive.
Timezone: The timezone for VA setup. Use the canonical ID (e.g. America/Chicago). You can use
this external article for reference.
Field | New prefix |
vsys | vsys |
Protocol | protocol |
source-ip | source-ip |
source-port | source-port |
destination-ip | destination-ip |
destination-port | destination-port |
time | time |
source-zone | source-zone |
destination-zone | destination-zone |
application-name | application-name |
rule-name | rule-name |
The Log format under the Configure Session Logs section must be set to Syslog.
Select the created template in the Session Log Content Format section.
The Log Format under the Configure Service Logs section must be set to Syslog.