Skip to content

Barracuda CloudGen

You can integrate Barracuda CloudGen with Sophos XDR so that it sends data to Sophos for analysis.

This page gives you an overview of the integration.

Barracuda CloudGen product overview

Barracuda CloudGen Firewall offers comprehensive security solutions for cloud and hybrid networks. It combines next-generation firewalling with site-to-site and client-to-site VPN connectivity, SD-WAN, and multi-layered defenses against ransomware and zero-day attacks, under centralized management across physical, virtual, and cloud deployments.

What we ingest

Sophos XDR collects Barracuda CloudGen Firewall syslog data by listening for messages your firewall forwards to a Sophos XDR data collector. The following log categories are collected:

  • Firewall traffic1: Allowed and blocked connection activity processed by the firewall.
  • Threat detections: Protocol and port violations and other threats the firewall identifies on inspected traffic.
  • VPN connection activity1: Site-to-site and client-to-site VPN connection events.
  • Authentication and access: Administrative login attempts and management sessions on the firewall.
  • Firewall configuration and management: Firewall operational and configuration events.

Event and data types

We ingest the following event and data types from Barracuda CloudGen:

  • Firewall traffic1: Allow, block, and drop decisions on network connections, including source and destination addresses and ports, NAT addresses, byte and packet counts, and application. Normalized to netflow telemetry.
  • Threat detections: Traffic the firewall flags as a protocol or port violation or other threat, with the action taken and the connection direction. Normalized to netflow and network intrusion detection telemetry.
  • VPN connection activity1: Site-to-site and client-to-site VPN connection events, including the firewall action and connection endpoints. Normalized to netflow telemetry.
  • Authentication and access: Administrative login attempts (allowed or denied) and management sessions, with source address, result, and failure reason. Normalized to authentication telemetry.
  • Firewall configuration and management: Firewall configuration and operational events. Normalized to management event telemetry.

Data provided by this integration

Data provided by Barracuda CloudGen gets normalized to the following schemas:

  • auth
  • managementevent
  • netflow 1
  • nids

For more information about using schemas in Data Lake Search, see Schemas and logical types.

Vendor documentation


  1. Netflow telemetry is only available with a Sophos Next-Gen SIEM subscription. See Sophos Next-Gen SIEM overview