Skip to content

[Filebeat] Add module for Forcepoint firewall logs #14663

Closed
@andrewkroh

Description

Add a fileset for ingesting logs from Forcepoint Next Generation Firewall (NGFW). The firewall can export CEF data over syslog (among other formats). So the fileset should be able to leverage the syslog input and the decode_cef processor to ingest the logs and then in a module apply the appropriate transformations to match ECS as much as possible.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Assignees

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions