# Elastic Security Integeration with Huawei firewall

**URL:** <https://discuss.elastic.co/t/elastic-security-integeration-with-huawei-firewall/293868>\
**Category:** SIEM\
**Created:** [January 10, 2022, 9:18am UTC](https://discuss.elastic.co/t/elastic-security-integeration-with-huawei-firewall/293868 "2022-01-10T09:18:38Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Rizwan\_Balouch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rizwan_balouch/32/97656_2.png) [@Rizwan\_Balouch](https://discuss.elastic.co/u/Rizwan_Balouch)\
**Post date:** [January 10, 2022, 9:18am UTC](https://discuss.elastic.co/t/elastic-security-integeration-with-huawei-firewall/293868/1 "2022-01-10T09:18:38Z")

</div>

any idea about elastic security integration with Huawei firewall ?  
any workaround as Huawei integration is not listed in elastic security builtin integrations ?

---

<div class="post-metadata">

**Author:** ![jamie.hynds](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jamie.hynds/32/84205_2.png) [@jamie.hynds](https://discuss.elastic.co/u/jamie.hynds)\
**Post date:** [January 10, 2022, 9:59am UTC](https://discuss.elastic.co/t/elastic-security-integeration-with-huawei-firewall/293868/2 "2022-01-10T09:59:37Z")

</div>

Hi @Rizwan_Balouch, unfortunately we do not currently have a Huawei firewall integration and isn't something we are currently working on. Looking at [their documentation](https://support.huawei.com/enterprise/en/doc/EDOC1000179232/ab247daa/how-do-i-configure-the-firewall-to-send-audit-logs-in-syslog-format-to-the-log-server), output to syslog is supported (presumably via UDP/TCP).

The custom UDP or TCP integrations could be used to ingest the logs via Elastic Agent, but events won't be automatically mapped to Elastic Common Schema, which is required to leverage your data within our solutions such as Elastic Security. You would need to build an Ingest Pipeline to parse and map the events.

 ![Screenshot 2022-01-10 at 09.56.00](https://us1.discourse-cdn.com/elastic/original/3X/b/9/b99f3725dec8966ec659e787115cb59982d53a96.png)

If you'd like to provide some log samples, we'd be happy to look at the format and advise on how to parse the events.

---

<div class="post-metadata">

**Author:** ![Rizwan\_Balouch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rizwan_balouch/32/97656_2.png) [@Rizwan\_Balouch](https://discuss.elastic.co/u/Rizwan_Balouch)\
**Post date:** [January 12, 2022, 9:27am UTC](https://discuss.elastic.co/t/elastic-security-integeration-with-huawei-firewall/293868/3 "2022-01-12T09:27:03Z")

</div>

Hi @jamie.hynds , Thanks for confirmation about Huawei Integration , i am working on Custom ingest pipelines to parse the Huawei Firewalls logs. Thanks

---

<div class="post-metadata">

**Author:** ![jamie.hynds](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jamie.hynds/32/84205_2.png) [@jamie.hynds](https://discuss.elastic.co/u/jamie.hynds)\
**Post date:** [January 12, 2022, 9:43am UTC](https://discuss.elastic.co/t/elastic-security-integeration-with-huawei-firewall/293868/4 "2022-01-12T09:43:08Z")

</div>

Thanks @Rizwan_Balouch - if we can help in any way just let me know. Also, if you're interested in contributing your pipeline, we can certainly work with you on a PR, with a few to using your pipeline as a starting point for a fully supported Huawei integration.

---

<div class="post-metadata">

**Author:** ![Rizwan\_Balouch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rizwan_balouch/32/97656_2.png) [@Rizwan\_Balouch](https://discuss.elastic.co/u/Rizwan_Balouch)\
**Post date:** [January 12, 2022, 10:10am UTC](https://discuss.elastic.co/t/elastic-security-integeration-with-huawei-firewall/293868/5 "2022-01-12T10:10:25Z")

</div>

Yes sure i will contribute Huawei Pipeline as a start point so other can use this as a starting point for a fully supported Huawei integrations.

Could you please share the necessary steps how i can start work with you on PR. Thanks

---

<div class="post-metadata">

**Author:** ![jamie.hynds](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jamie.hynds/32/84205_2.png) [@jamie.hynds](https://discuss.elastic.co/u/jamie.hynds)\
**Post date:** [January 12, 2022, 10:23am UTC](https://discuss.elastic.co/t/elastic-security-integeration-with-huawei-firewall/293868/6 "2022-01-12T10:23:43Z")

</div>

Sounds good, thanks Rizwan. You can view our contributing guide for Elastic Agent integrations here: [integrations/CONTRIBUTING.md at master · elastic/integrations · GitHub](https://github.com/elastic/integrations/blob/master/CONTRIBUTING.md)

A good example of a community user PR is a recent Cloudflare integration submitted by @legoguy1000: [[Cloudflare] Cloudflare audit logs by legoguy1000 · Pull Request #2294 · elastic/integrations · GitHub](https://github.com/elastic/integrations/pull/2294)

---

<div class="post-metadata">

**Author:** ![Rizwan\_Balouch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rizwan_balouch/32/97656_2.png) [@Rizwan\_Balouch](https://discuss.elastic.co/u/Rizwan_Balouch)\
**Post date:** [January 12, 2022, 10:25am UTC](https://discuss.elastic.co/t/elastic-security-integeration-with-huawei-firewall/293868/7 "2022-01-12T10:25:14Z")

</div>

Thank you @jamie.hynds🙂

---

<div class="post-metadata">

**Author:** ![mohammadawaisjavaid](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mohammadawaisjavaid/32/60807_2.png) [@mohammadawaisjavaid](https://discuss.elastic.co/u/mohammadawaisjavaid)\
**Post date:** [January 14, 2022, 10:02am UTC](https://discuss.elastic.co/t/elastic-security-integeration-with-huawei-firewall/293868/8 "2022-01-14T10:02:59Z")

</div>

Greetings. I have read the solution its quite impressing. I just want to know that is there a webinar or something like that happened on this topic that how to use custom logs integration and then how can we seperate the pipelines. If yes then it would a great favor indeed.

Looking forward hearing from you.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 11, 2022, 10:03am UTC](https://discuss.elastic.co/t/elastic-security-integeration-with-huawei-firewall/293868/9 "2022-02-11T10:03:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
