Monitoring Firewalls with Splunk
Introduction to Firewall Log Analysis Using Splunk
Objective: Demonstration of firewall log analysis using Splunk.
Agenda Overview: Focus on four main aspects:
Understanding firewalls
Overview of firewall logs
Firewall log analytics using Splunk
Utility of Splunk in log analysis
Understanding Firewalls
Definition: A firewall is a network security mechanism designed to restrict unauthorized access to or from a private network.
Functions of a Firewall:
Monitoring network traffic.
Controlling the flow of data.
Diagram Overview: Various communication devices are connected to a modem, and the firewall restricts network traffic going to and from the internet.
Purpose: Control unauthorized access to public networks.
Firewall Logs
Types of Firewall Logs: Firewalls generate various types of logs, including but not limited to:
Traffic Logs
System Monitoring Logs
DHCP Logs
Security Policy Logs
Control Logs
Sample Traffic Log Event: Shows various pieces of information including:
Device IP
Hostname
MAC Address
Other relevant log information
Visualizing Log Information on Splunk Dashboard
Overview of Splunk Dashboard: Comprised of four main panels that provide different insights into firewall operations.
Panel 1: Firewall Device Information
Purpose: Provides information related to hardware used within the company's network environment.
Details Shown:
Hostname
Firmware version
Model name
Device ID
Example Device Used for Demonstration: Zyxel Zywall Firewall
Panel 2: Network Traffic Panel
Functionality: Displays the amount of data uploaded and downloaded on a daily and weekly basis.
Panel 3: Data Usage Panel
Overview: Offers a customized view of incoming and outgoing data.
Features:
Divided by connected devices.
Drilldown functionality to select specific employee data and connected devices.
Panel 4: Security Breach Attempts
Description: Gives insight into unauthorized access attempts.
Included Information:
List of attackers attempting to gain unauthorized access.
Blocked IP addresses recorded by the firewall.
Automated Monitoring and Alert Mechanism in Splunk
Feature of Splunk: Facilitates automated monitoring through an alert mechanism.
Types of Alerts:
Data upload and download monitoring, triggering alerts if limits are exceeded.
Monitoring usage on laptops and mobile devices.
Admin Notifications: Administrators are notified via email when alerts are triggered.
Example: Sample email snippet showcasing notification details.
Benefits of Using Splunk for Firewall Log Analysis
Bird's Eye View: Provides essential information at a glance, making it easier for administrators to monitor data.
Real-Time Insights: Facilitate real-time insights of data in a single dashboard with multiple panels.
Efficiency in Monitoring: Allows administrators to visualize and monitor large volumes of data at a faster processing rate.
Customization and Ease of Use: Offers handy customization features making it an economical solution to maintain.
Actual Dashboard Overview
Avotrix Firewall Monitor Dashboard: An example of a real dashboard showcasing the following panels:
Firewall Device Information:
Displays hostname, version, model name, and device ID.
Network Traffic Panel:
Shows daily and weekly data upload and download statistics.
Data Usage Panel:
Customized view with drilldowns for user and device selection.
Security Breach Attempts:
Displays login attempts and blocked IP addresses by the firewall.
Conclusion and Call to Action
Summary of Video Content: Covered aspects of firewall log analysis using Splunk, including practical demonstrations.
Encouragement to View More Content: Invite viewers to stay tuned for more Splunk use case videos.
Subscription Request: Viewers are encouraged to subscribe and enable notifications for updates on new content.