Quickstart
Barracuda WAF Syslog
Barracuda WAF Syslog
Updated 2026-08-17
Barracuda WAF Syslog
Automation Guide for Bloo
1. Overview
This article describes the steps to configure Barracuda WAF Syslog with Bloo.
The following properties are specific to the Barracuda Networks WAF:
- Collection method: Syslog
- Format: Regex
- Functionality: Web Application Firewall
2. Prerequisites
Before you connect Barracuda Networks WAF, obtain the IP address of the Remote Server (Bloo) and verify that firewalls between the Barracuda appliance and Remote Server allow UDP traffic on port 514.
3. Configure Facilities for Each Log Type
- Navigate to the ADVANCED > Export Logs page.
- In the Export Logs section, click Export Log Settings. The Export Log Settings window opens.
- In the Syslog Settings section, select the appropriate facility for each log type from the drop-down list below, then click Save.
| Option | Description |
|---|---|
| Web Firewall Logs Facility | Select a syslog facility between Local0 and Local7. |
| Access Logs Facility | Select a syslog facility between Local0 and Local7. |
| Audit Logs Facility | Select a syslog facility between Local0 and Local7. |
| System Logs Facility | Select a syslog facility between Local0 and Local7. |
4. Add the Export Log Server
- Click Add Export Log Server in the Export Logs section. The Add Export Log Server window opens.
| Info: Current Barracuda WAF firmware requires selecting Log Server Type: Syslog NG in this window — there is no longer a plain "Syslog" option. If your firmware is older, you may not see this field; use whichever syslog-type option is available. |
Specify values for the following:
| Option | Description |
|---|---|
| Name | The name of the Remote Console or Event Collector. |
| Log Server Type | Select Syslog NG (on current firmware). |
| Syslog Server | The IP address of your Remote Server (Bloo) or Event Collector. |
| Port | The port that is associated with the IP address of your Remote Server or Event Collector. If syslog messages are sent by UDP, use the default port, 514. |
| Connection Type | The connection type transmits the logs from the Barracuda Web Application Firewall to the Remote Server or Event Collector. UDP is the default protocol for syslog communication. |
| Validate Server Certificate | No |
- Select Yes from the Log Unit Name option.
- Select the default format from the list box for the following log types in the Log Formats pane:
- Web Firewall Logs Format
- Access Logs Format
- Audit Logs Format
- Network Firewall Logs Format
- System Logs Format
- Click Save Changes.
- Go to Menu > Basic > Administration.
- Click Restart from the System/Reload/Shutdown pane.
5. Configuring Syslog Connector in Bloo
| Info: By default, a Syslog Connector is already configured and present in the Data Source with a listener port on 514. If it is not present, only then proceed with the steps below to configure a new syslog connector. |
- Go to System > Data Sources.
- Click the '+' icon in the top right corner to add a new data source.
- Select Syslog and then click Next.
- Provide a suitable name for the Syslog Connector.
- Provide the Listener port value as '514'.
- Click Next.
Related Links
Related
Was this page helpful?