ManageEngine Log 360 is a Security Information and Event Management (SIEM) solution that helps enhance network security and ensure compliance with regulatory requirements by collecting and analyzing logs. By integrating Firewall Analyzer with Log 360, administrators can forward critical logs to Log360 for advanced analysis, enabling deeper insights into user activity, anomaly detection, and potential threat identification.
NOTE: Log360 (v13000 and above) is compatible with Firewall Analyzer v128707 and later.
To integrate Firewall Analyzer with Log 360, follow the steps below:


By integrating Firewall Analyzer with Log 360, network admins can leverage the following functionalities:
Centralized log collection and analysis are essential for compliance with standards such as HIPAA, PCI-DSS, and others. By forwarding Firewall Analyzer logs to Log360, administrators can ensure proper auditing and adherence to regulatory requirements.
By forwarding access and debug logs to Log360, administrators gain visibility into user activities within Firewall Analyzer. Correlating these logs helps in identifying anomalies, troubleshooting issues, and strengthening overall security posture.
Once Firewall Analyzer is integrated with Log 360, access and debug logs are automatically forwarded to the Log360 server via Syslogs. These logs can be visualized in the form of the following reports:
NOTE:
Log360 uses both UDP and TCP ports to receive syslogs. By default, ports such as UDP 514, UDP 513, TCP 514, and TCP 513 are used. These ports can be customized if required.
The product activity report category contains the All Activity report, which provides a consolidated view of all logs forwarded from the Firewall Analyzer server.
The following debug reports can be generated from the debug logs of Firewall Analyzer:
These reports provide insights into user access patterns within the product, including login activities and interactions with the Firewall Analyzer interface.
The User Audit Reports provides visibility into user activities and administrative actions in Firewall Analyzer, including authentication events, configuration changes, and user lifecycle operations. It helps track key activities such as user logins and logouts, creation and deletion of user accounts, and modifications to roles and permissions. Additionally, it captures important system changes like device additions and configuration updates, enabling administrators to monitor access, maintain compliance, and detect unauthorized actions.