Sophos XG Firewall

When you configure your Sophos XG Firewall to send log data to USM Appliance, you can use the Sophos XG plugin to translate raw log data into normalized events for analysis. The table below provides some basic information for the plugin.

Plugin Information
Device Details
Vendor Sophos
Device Type Firewall
Connection Type Syslog
Data Source Name Sophos XG
Data Source ID 1747

Integrating Sophos XG

Before you configure the Sophos XG integration, you must have the IP Address of the USM Appliance Sensor.

To configure Sophos XG to send log data to USM Appliance

  1. In the Sophos XG console, go to System > System Services > Log Settings and, under the Syslog Servers section, click Add.
  2. Enter the server details:

    • Name — Unique name for your instance.
    • IP Address / Domain — Specify the IP address (IPv4 or IPv6)/ domain for your sensor.
    • Port — 514
    • Facility — Syslog facility for logs sent to the Sensor. Facility indicates to the source of a log such as the operating system, the process or an application. It is defined by the syslog protocol.

      The device supports several syslog facilities for received logs.

      Available options:

      • DAEMON
      • KERNEL
      • LOCAL0 - LOCAL7
      • USER
      • Severity Level:

        • EMERGENCY — System is not usable
        • ALERT — Action must be taken immediately
        • CRITICAL — Critical condition
        • ERROR — Error condition
        • WARNING — Warning condition
        • NOTIFICATION — Normal but significant condition
        • INFORMATION — Informational
        • DEBUG — Debug level messages.

    Unless a specific device format is chosen, the device produces logs in its standard format.

    Note: You can configure a maximum of five syslog servers.

  3. Click Save.
  4. On System > System Services > Log Settings, enable all those logs that you want sent to the sensor.

Plugin Enablement

For plugin enablement information, see Enable Plugins.

Additional Resources and Troubleshooting

For troubleshooting, refer to the vendor documentation: