Loading

Sophos Integration

<div class="condensed-table">
| | |
| --- | --- |
| Version | 3.10.0 (View all) |
| Compatible Kibana version(s) | 8.6.1 or higher |
| Supported Serverless project types
What’s this? | Security
Observability |
| Subscription level
What’s this? | Basic |
| Level of support
What’s this? | Elastic |

</div>
The Sophos integration collects and parses logs from Sophos Products.

Currently, it accepts logs in syslog format or from a file for the following devices:

To configure a remote syslog destination, please reference the SophosXG/SFOS Documentation.

The syslog format chosen should be Default.

This module has been tested against SFOS version 17.5.x and 18.0.x. Versions above this are expected to work but have not been tested.

The utm dataset collects Unified Threat Management logs. Currently, it collects the following log categories: DNS, DHCP, HTTP and Packet Filter.

This is the Sophos xg dataset. Reference information about the log formats can be found in the Sophos syslog guide.

The format of timezones added to Sophos XG logs do not always match the expected formats used in common programming languages, and therefore 2 options have been added to the integration configuration:

  1. Timezone - This option allows the user to specify the timezone that the logs will be translated to. This will enforce all logs sent to the integration to the same timezone. This option is recommended for most users and default is UTC.
  2. Timezone Map - This option is for users who have logs from multiple timezones and want to translate them to the correct timezone. This option allows the user to specify a map of timezones to translate from and to. This option is recommended for advanced users who have logs from multiple timezones being sent to the same integration instance.