Barracuda WAF (v1.0.7)

Barracuda WAF modeling rules and parsing rules for XSIAM

Author
Cortex XSOAR
Support
xsoar
URL
https://www.paloaltonetworks.com/cortex
Categories
Analytics & SIEM

Modeling rules (1)

Parsing rules (1)

README

Barracuda WAF

This pack includes Cortex XSIAM content.

Configuration on Server Side

In Barracuda WAF appliance:

  1. Go to the ADVANCED > Export Logs page.
  2. In the Export Logs section, click Add Export Log Server. The Add Export Log Server window opens. Specify values for the following:
  1. In the Logs Format section, specify values for the following fields:

Supported log formats: raw syslog

For more information on exporting log formats

  1. Click Save.

Collect Events from Vendor

In order to use the collector, use the Broker VM option.

Broker VM

To create or configure the Broker VM, use the information described here.

You can configure the specific vendor and product for this instance.

  1. Navigate to Settings > Configuration > Data Broker > Broker VMs.
  2. Right-click, and select Syslog Collector > Configure.
  3. When configuring the Syslog Collector, set the following values:
    • vendor as vendor - barracuda
    • product as product - waf