Skip to content

Barracuda WAF

You can integrate Barracuda WAF with Sophos XDR so that it sends data to Sophos for analysis.

This page gives you an overview of the integration.

Barracuda WAF product overview

Barracuda Web Application Firewall (WAF) protects applications, APIs, and mobile app backends against a variety of attacks, including OWASP Top 10 attacks, zero-day threats, data leakage, and application-layer denial-of-service (DoS) attacks.

What we ingest

Sophos XDR collects Barracuda WAF syslog data by listening for messages your WAF forwards to a Sophos XDR data collector. The following log categories are collected:

  • Web application firewall activity: Web requests that the WAF inspects and the actions it takes, including attack detections and web access transactions.
  • Administration and audit: Administrative and configuration audit activity on the WAF, including authentication.
  • Network traffic1: Connection and flow records emitted by the WAF.

Event and data types

We ingest the following event and data types from Barracuda WAF:

  • Web application firewall activity: Web requests inspected by the WAF and the actions taken, including attack detections (such as OWASP Top 10 and other web attacks) and web access transactions, with the URL, method, action, and client. Normalized to HTTP telemetry.
  • Administration and audit: Administrative and configuration audit activity on the WAF, including authentication events. Normalized to authentication and HTTP telemetry.
  • Network traffic1: Connection and flow records emitted by the WAF. Normalized to netflow telemetry.

Data provided by this integration

Data provided by Barracuda WAF gets normalized to the following schemas:

  • auth
  • http
  • netflow 1

For more information about using schemas in Data Lake Search, see Schemas and logical types.

Vendor documentation


  1. Netflow telemetry is only available with a Sophos Next-Gen SIEM subscription. See Sophos Next-Gen SIEM overview