Firewall Analyzer supports Sidewinder G2.
/etc/sidewinder/auditd.confsyslog (local0 filters[“NULL”] sef) You can use ‘local0’ through ‘local7’ as names for the facility; they are predefined in syslogd.
/etc/syslog.conflocal0.* @<server_name> at the end, where facility local0 matches the facility mentioned in step 2 and <server_name> is the name of the machine where Firewall Analyzer is running.pss syslogkill -HUP <syslog process ID>cf server restart auditdThe Sidewinder G2 will now send audit data to Firewall Analyzer.
Thank you for your feedback!