Loading

Juniper SRX integration

<div class="condensed-table">
| | |
| --- | --- |
| Version | 1.21.3 (View all) |
| Compatible Kibana version(s) | 8.0.0 or higher |
| Supported Serverless project types
What’s this? | Security
Observability |
| Subscription level
What’s this? | Basic |
| Level of support
What’s this? | Elastic |

</div>
This is an integration for ingesting logs from Juniper SRX.

The SRX Log integration only supports syslog messages in the format "structured-data + brief". See the JunOS Documentation on structured-data.

To configure a remote syslog destination, please reference the SRX Getting Started - Configure System Logging. The syslog format choosen should be Default.

The following processes and tags are supported:

JunOS processes JunOS tags
RT_FLOW RT_FLOW_SESSION_CREATE
RT_FLOW_SESSION_CLOSE
RT_FLOW_SESSION_DENY
APPTRACK_SESSION_CREATE
APPTRACK_SESSION_CLOSE
APPTRACK_SESSION_VOL_UPDATE
RT_IDS RT_SCREEN_TCP
RT_SCREEN_UDP
RT_SCREEN_ICMP
RT_SCREEN_IP
RT_SCREEN_TCP_DST_IP
RT_SCREEN_TCP_SRC_IP
RT_UTM WEBFILTER_URL_PERMITTED
WEBFILTER_URL_BLOCKED
AV_VIRUS_DETECTED_MT
CONTENT_FILTERING_BLOCKED_MT
ANTISPAM_SPAM_DETECTED_MT
RT_IDP IDP_ATTACK_LOG_EVENT
IDP_APPDDOS_APP_STATE_EVENT
RT_AAMW SRX_AAMW_ACTION_LOG
AAMW_MALWARE_EVENT_LOG
AAMW_HOST_INFECTED_EVENT_LOG
AAMW_ACTION_LOG
RT_SECINTEL SECINTEL_ACTION_LOG