These are the general steps you should follow to configure a syslog server on a WatchGuard Firewall to send all metadata to Lumu:
All the detailed steps and guidance to create, download, and install a virtual appliance on your preferred hypervisor or Cloud solution are available in our documentation:
Go to the Lumu Virtual Appliance and refresh the VA Collectors settings by running the command
lumu-appliance collectors refresh
. If the appliance is running, it should be stopped for setting up collectors.
Select the option that refers to WatchGuard Firewall and the format that suits you best, then inform the following data:
Once you have installed and configured a Lumu Virtual Appliance with the respective firewall collector, the next step is to set up WatchGuard to forward firewall metadata to Lumu. You can find all the details about setting up syslog server on WatchGuard Firebox in their official documentation: