The Snare Server is capable of receiving logs from CyberGuard Firewalls (generally the WELF file format) via the syslog protocol.
The Snare Server can filter on a wide variety of fields within the CyberGuard source data, including:
- Date/Time
- Source Address
- Destination Address
- Destination Port
- Packet ReturnCode (success/failure/information)
- Source Firewall
- Action (accept / drop)
- Source Interface
- Source Port
- Protocol
Snare can provide drill-down access to the raw log data, via overview components such as a '15 minute pattern map', and horizontal bar graphs by source/destination/destination port.
Aug 3 02:30:11 172.16.8.9 auditlogd: Activity: deny 2004/08/03 02:30:10: D dec2 lo0 192.168.104.10 192.168.104.255 17 137 137