Juniper Networks Firewall and VPN

The Juniper Networks Firewall and VPN DSM for IBM® QRadar® accepts Juniper Firewall and VPN events by using UDP syslog.

About this task

QRadar records all relevant firewall and VPN events.

Note: TCP syslog is not supported. You must use UDP syslog.

You can configure your Juniper Networks Firewall and VPN device to export events to QRadar.

Procedure

  1. Log in to your Juniper Networks Firewall and VPN user interface.
  2. Select Configuration > Report Settings > Syslog.
  3. Select the Enable Syslog Messages check box.
  4. Type the IP address of your QRadar Console or Event Collector.
  5. Click Apply.

    You are now ready to configure the log source in QRadar.