Hub
Network

WatchGuard Firebox Traffic Logs

WatchGuard Firebox traffic log messages (3000-0148, 3000-0176) of one Firebox between a trusted LAN and the internet, with the Mobile VPN with SSL portal on its external address, as ECS JSON with the native Traffic Monitor message in event.original. About 7,100 records a day, from 140 an hour at night to 660-680 an hour around 12:00-13:00 UTC. For SIEM content on perimeter firewall telemetry. Recurring episodes show one external address denied on three or more Firebox ports and then reaching the SSL VPN portal.

Quick Start

uv tool install eventum-generator
git clone https://github.com/eventum-generator/content-packs.git
cd content-packs
eventum generate \
  --path generators/network-watchguard-firebox/generator.yml \
  --id firebox \
  --live-mode true

Event Types

Event IDDescriptionFrequencyCategory
3000-0148 Outgoing-00Allow, first packet, TCP/443 to the internet with source NAT52.01% of recordsnetwork
3000-0148 Unhandled External Packet-00Deny, TCP from the internet to the Firebox28.44% of recordsnetwork
3000-0176 HTTP-proxy-00Allow, HTTP proxy connection terminated9.24% of recordsnetwork
3000-0148 WatchGuard SSLVPN-00Allow, first packet, TCP/443 from the internet to the Firebox6.45% of recordsnetwork
3000-0148 Ping-00Deny, ICMP echo request from the LAN to the Firebox3.86% of recordsnetwork

Realism Features

  • One Firebox between a trusted LAN (Trusted, 10.0.1.0/24) and the internet (External), with the SSL VPN portal on its external address. LAN clients during the working day produce 3,500 records a day (5% day-to-day variation) on a curve that rises from 07:00, peaks at 12:00-13:00 UTC and falls off by 19:00; always-on LAN hosts, about a quarter of the clients, add 1,100 a day flat and carry all LAN traffic at night; the portal takes 460 connections a day, 50-60 an hour at midday and 2-3 at night; unsolicited packets from the internet arrive at 85 an hour (10% hour-to-hour variation). Hourly volumes are the same in both modes.
  • A LAN record is HTTPS to one of up to 40 internet servers with skewed popularity, allowed by Outgoing-00 with source NAT (82.5%), HTTP through HTTP-proxy-00 logged when the connection ends, with flags, duration (median 4 s), packet and byte counters (14.6%), or 1, 2 or 4 echo requests to the Firebox denied by Ping-00 (2.9%). Clients differ in activity by a fixed weight, so a few clients carry most of the traffic.
  • 150 external addresses, each with a role and operating system: 97 remote users behind home routers carry the bulk of portal connections and send stray packets on one or two ports (65:35); 15 carrier-grade and cloud NAT egress addresses carry a few portal connections a day each and probe one to five ports (52:28:12:5:3); 38 hosting and scanning ranges send most multi-port probes (39:21:20:12:8) and reach the portal at a tenth of a user's rate. A probe sends 1-3 SYNs to each port, 60% of probes come from a stateless-scanner stack (TTL 255, no TCP options), and all are denied as Unhandled External Packet-00; a portal connection is followed by 0-2 further connections of the same address. TTLs, window sizes and TCP header offsets follow the address's operating system.
  • Allow records of 3000-0148 mark the first packet of a connection and carry packet length, TTL and tcp_info, with no duration or counters. Each record copies the positional fields and key order of one vendor example, since WatchGuard publishes no complete field specification; optional Log Catalog fields (route_type, src_user, application control, proxy request details) are not generated. The TCP Deny shape comes from a 2022 example without flags, duration or counters, which Fireware 12.10.3 and later may add. Ports without a vendor example use IANA service names; port 9007 appears as a number. WatchGuard SSLVPN-00 and Outgoing-00 apply the documented -00 suffix; no published Elastic mapping exists to follow.
  • Only traffic messages: no FireCluster member field, no event, alarm, authentication or VPN tunnel messages, no IPv6, no Syslog header or serial number, no IBM LEEF. The Firebox time zone is UTC with one-second timestamps. Records that belong to one moment are seconds apart rather than milliseconds: repeated SYNs to one port are 7 s apart at the median during the day and about 18 s at night, where a real TCP stack retries after 1-3 s. Rates, sizes, durations and address pools are training assumptions, not measured production values.
  • Every external address, port and record type of the chain occurs in ordinary traffic in both modes, and no field labels an episode: shared and scanning addresses probe three or more ports, and the same addresses reach the portal at other times. Outside episodes an address denied on three or more ports never reaches the portal within the next hour and often sends a lone denied SYN to the former portal port 9007 in that hour instead (about 7 a day in both modes). With anomaly_mode true, counts of chain parts are about one per episode higher while total volumes stay the same. A shared address probes three or more ports about once in two days, so in a 4-day window an episode address may show no other such probe.

Sample Output

{
  "@timestamp": "2026-09-01T13:22:48+00:00",
  "destination": {
    "ip": "203.0.113.250",
    "port": 443
  },
  "ecs": {
    "version": "8.17.0"
  },
  "event": {
    "action": "traffic_allow",
    "category": [
      "network"
    ],
    "code": "3000-0148",
    "dataset": "watchguard.firebox.traffic",
    "kind": "event",
    "original": "2026-09-01 13:22:48 Allow 192.0.2.216 203.0.113.250 https/tcp 61293 443 External Firebox Allowed 64 42 (WatchGuard SSLVPN-00) proc_id=\"firewall\" rc=\"100\" tcp_info=\"offset 11 S 944686688 win 65535\" msg_id=\"3000-0148\"",
    "type": [
      "connection",
      "allowed"
    ]
  },
  "network": {
    "transport": "tcp"
  },
  "observer": {
    "egress": {
      "interface": {
        "name": "Firebox"
      }
    },
    "ingress": {
      "interface": {
        "name": "External"
      }
    },
    "name": "firebox-edge",
    "product": "Firebox",
    "type": "firewall",
    "vendor": "WatchGuard"
  },
  "related": {
    "ip": [
      "192.0.2.216",
      "203.0.113.250"
    ]
  },
  "rule": {
    "name": "WatchGuard SSLVPN-00"
  },
  "source": {
    "ip": "192.0.2.216",
    "port": 61293
  },
  "watchguard": {
    "firebox": {
      "disposition": "Allow",
      "dst_interface": "Firebox",
      "process": "firewall",
      "return_code": "100",
      "src_interface": "External"
    }
  }
}

Parameters

ParameterDefaultDescription
anomaly_modetrueAdd periodic episodes to the background; false emits the background only
anomaly_interval_hours24Episode interval in source hours, 2-8760
device_namefirebox-edgeobserver.name (not part of the native message)
firebox_external_ip203.0.113.250Firebox external address: source NAT, portal and denied destination
firebox_trusted_ip10.0.1.1Firebox trusted address, destination of denied pings
external_interfaceExternalExternal interface name in the message
trusted_interfaceTrustedTrusted interface name in the message
client_prefix10.0.1.Client addresses are this prefix plus a host number
client_first20First client host number
client_count120Number of LAN clients (at least 8; client_first + client_count at most 255)

Related Generators