Skip to content

To share Microsoft Sentinel content related to WatchGuard Fireware devices

License

Notifications You must be signed in to change notification settings

acd84/WatchGuardFireware

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

14 Commits
 
 
 
 
 
 

Repository files navigation

WatchGuardFireware

ASIM parsers to be used with Fireware devices.

  • ASimNetworkSessionWatchGuardFireware: parse all the events (allowed and denied).
  • ASimNetworkSessionWatchGuardFireware - Denied Events: parse only the denied events.

If you have deployed a Firecluster configuration (two or more devices in a failover structure), it will require a minor change to parse the "firecluster member" reporting the log (in the works).

Also, a version that will accept parameters is in the works.

It can be added to Microsoft Sentinel by using the following ASIM empty custom unifying parsers: https://github.com/Azure/Azure-Sentinel/tree/master/ASIM/deploy/EmptyCustomUnifyingParsers

About

To share Microsoft Sentinel content related to WatchGuard Fireware devices

Topics

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published