Sophos XG Firewall is formerly known as Sophos Astaro Security Gateway.
The DSM RPM name remains as Sophos Astaro Security Gateway. The Sophos XG Firewall DSM for IBM
QRadar accepts events by using
syslog, enabling QRadar to
record all relevant events.
About this task
To configure syslog for Sophos XG Firewall:
Procedure
- Log in to the Sophos XG Firewall console.
- From the navigation menu, select .
- Under the Syslog server section, click
Add.
- Configure the following parameters:
- Name - Type a name for the syslog
server.
- IP address/domain: IP address or domain name of the syslog
server. Logs are sent to this server
- Secure log transmission: Encrypts logs sent to the syslog
server using TLS.
- Port: Typically 514 (for UDP/TCP) or a secure TLS
port.
- Facility: Facilities reflect the names of processes and
daemons, and inform the syslog server of the origin of the log.
- DAEMON: Processes running as daemon service
- KERNEL: Kernel processes
- USER: Processes started by signed-in users
- LOCAL0-LOCAL7: You can use these for your own purposes. Example: If you
configure LOCAL1 for firewall 1 and LOCAL2 for firewall 2, the syslog server receives the respective
facility value along with the log.
- Security Level: Minimum severity level of messages reported.
Sophos Firewall logs all messages with a severity level equal to or greater than the level you
select. For example, select Error to log all messages tagged as error and all
messages tagged as critical, alert, and emergency. Select Debug to include
all messages. Alert means that action must be taken immediately. This has a
higher severity level than Critical.
- Format: Log format. Third-party syslog servers can use either
of the following log formats:
- Standard syslog protocol: Central reporting only uses this format.
-
Central Reporting Format has been renamed to Standard syslog
protocol.
- Device standard format (legacy): A custom format in which the number of
log data fields differs for each module
- Click Save.
- Go to Log settings and select the logs you want to send to the
syslog server. You can now configure the log source in QRadar.
- To configure QRadar
to receive events from your Sophos XG Firewall device, from the Log Source
Type list, select Sophos XG Firewall.
- You can use the sample event messages from Sophos XG
Firewall sample event messages to verify a successful integration with IBM
QRadar.