Cyfin is installed on a
server, not on the SonicWALL appliance
Log File Setup
Log File Type: SonicWALL Security Appliance
SonicWALL Configuration Steps
In order to get SonicWALL Web traffic URLs into the Cyfin syslog, you must first have the SonicWALL Content Filtering Service enabled. You must also enforce the Content Filtering Service within the zone (LAN) in which your traffic will be forwarded. In order to get the service enabled and enforced, follow the steps below:
Log on to your SonicWALL interface.
Go to Security Services – Content Filter – Configure.
Select the Log Access to URL box.
Go to Network – Zones. Find the LAN zone and click Configure.
Select the Enforce Content Filtering Service box.
Apply all changes above.
To verify that the changes were made successfully, you can make a copy of the raw syslogs that are generated after the change. These files are in the write location of your Cyfin installation (default location is …Wavecrest\Cyfin\wc\cf\log). You should see files being written called syslogXXXXXXXX.txt, if you have already configured the Cyfin setup correctly.
Make a copy of the most recent file after the change, and use a text editor (Notepad++ works well) to open the file. Search for the fields dstname= and arg= to confirm that they exist. You can use Ctrl+F to find these strings. You may need to wait for a short time after making the changes for them to take effect.
Cyfin Configuration Steps
Cyfin Syslog Server listens for syslog messages from your SonicWALL device. Both UDP-based and TCP-based messages are supported.
Select the SonicWALL Syslog log file configuration in Cyfin for your SonicWALL device.
Specify the Directory in which the log files will be created. The default directory is C:\Program Files\Wavecrest\Cyfin\wc\cf\log.
Select Enable Syslog Server.
For Port Type, select UDP or TCP for the Internet protocol you want to use.
In the Listening Port field, the default port number is 1455. The listening port will be used by your SonicWALL device to transfer the data. You may change this number if necessary.
At your SonicWALL device, specify the IP address of the Cyfin server and the listening port, and submit the syslog messages.
Your log files will be created and displayed in the Log File Viewer in Cyfin.
If you have many of the same SonicWALL devices, use one log file configuration with one listening port, and point each SonicWALL device to the same listening port.