Sophos XG Firewall

Sophos XG Firewall is formerly known as Sophos Astaro Security Gateway. The DSM RPM name remains as Sophos Astaro Security Gateway. The Sophos XG Firewall DSM for IBM QRadar accepts events by using syslog, enabling QRadar to record all relevant events.

About this task

To configure syslog for Sophos XG Firewall:

Procedure

  1. Log in to the Sophos XG Firewall console.
  2. From the navigation menu, select System services > Log Settings.
  3. Under the Syslog server section, click Add.
  4. Configure the following parameters:
    1. Name - Type a name for the syslog server.
    2. IP address/domain: IP address or domain name of the syslog server. Logs are sent to this server
    3. Secure log transmission: Encrypts logs sent to the syslog server using TLS.
    4. Port: Typically 514 (for UDP/TCP) or a secure TLS port.
    5. Facility: Facilities reflect the names of processes and daemons, and inform the syslog server of the origin of the log.
      • DAEMON: Processes running as daemon service
      • KERNEL: Kernel processes
      • USER: Processes started by signed-in users
      • LOCAL0-LOCAL7: You can use these for your own purposes. Example: If you configure LOCAL1 for firewall 1 and LOCAL2 for firewall 2, the syslog server receives the respective facility value along with the log.
    6. Security Level: Minimum severity level of messages reported. Sophos Firewall logs all messages with a severity level equal to or greater than the level you select. For example, select Error to log all messages tagged as error and all messages tagged as critical, alert, and emergency. Select Debug to include all messages. Alert means that action must be taken immediately. This has a higher severity level than Critical.
    7. Format: Log format. Third-party syslog servers can use either of the following log formats:
      • Standard syslog protocol: Central reporting only uses this format.
      • Central Reporting Format has been renamed to Standard syslog protocol.
      • Device standard format (legacy): A custom format in which the number of log data fields differs for each module
  5. Click Save.
  6. Go to Log settings and select the logs you want to send to the syslog server. You can now configure the log source in QRadar.
  7. To configure QRadar to receive events from your Sophos XG Firewall device, from the Log Source Type list, select Sophos XG Firewall.
  8. You can use the sample event messages from Sophos XG Firewall sample event messages to verify a successful integration with IBM QRadar.