When you configure Sophos XG Firewall to send log data to USM Appliance, you can use the Sophos XG plugin to translate raw log data into normalized events for analysis. The table below provides some basic information for the plugin:
|Data Source Name||Sophos XG|
|Data Source ID||1747|
Integrating Sophos XG
Before you configure the Sophos XG integration, you must have the IP Address of the USM Appliance Sensor.
To configure Sophos XG to send log data to USM Appliance
- In the Sophos XG console, go to System > System Services > Log Settings and, under the Syslog Servers section, click Add.
Enter the server details:
- Name — Unique name for your instance.
- IP Address / Domain — Specify the IP address (IPv4 or IPv6)/ domain for your sensor.
- Port — 514
Facility — Syslog facility for logs sent to the Sensor. Facility indicates to the source of a log such as the operating system, the process or an application. It is defined by the syslog protocol.
The device supports several syslog facilities for received logs.
- LOCAL0 - LOCAL7
- EMERGENCY — System is not usable
- ALERT — Action must be taken immediately
- CRITICAL — Critical condition
- ERROR — Error condition
- WARNING — Warning condition
- NOTIFICATION — Normal but significant condition
- INFORMATION — Informational
- DEBUG — Debug level messages.
Unless a specific device format is chosen, the device produces logs in its standard format.
Note: You can configure a maximum of five syslog servers.
- Click Save.
On System > System Services > Log Settings, enable all those logs that you want sent to the sensor.
For plugin enablement information, see Enable Plugins.
Additional Resources and Troubleshooting
For troubleshooting, refer to the vendor documentation: