When you configure Sophos XG Firewall to send log data to USM Anywhere, you can use the Sophos XG plugin to translate the raw log data into normalized events for analysis.
Integrating Sophos XG
Before you configure the Sophos XG integration, you must have the IP Address of the USM Anywhere Sensor.
To configure Sophos XG to send log data to USM Anywhere
- In the Sophos XG console, go to System > System Services > Log Settings and, under the Syslog Servers section, click Add.
Enter the server details:
- Name — Unique name for your instance.
- IP Address / Domain — Specify the IP address (IPv4 or IPv6)/ domain for your sensor.
- Port — 514
Facility — Syslog facility for logs sent to the Sensor. Facility indicates to the source of a log such as the operating system, the process or an application. It is defined by the syslog protocol.
The device supports several syslog facilities for received logs.
- LOCAL0 - LOCAL7
- EMERGENCY — System is not usable
- ALERT — Action must be taken immediately
- CRITICAL — Critical condition
- ERROR — Error condition
- WARNING — Warning condition
- NOTIFICATION — Normal but significant condition
- INFORMATION — Informational
- DEBUG — Debug level messages.
Unless a specific device format is chosen, the device produces logs in its standard format.
Note: You can configure a maximum of five syslog servers.
- Click Save.
On System > System Services > Log Settings, enable all those logs that you want sent to the sensor.
The Sophos XG plugin automatically processes all messages when the raw message contains "date=\\S+\\s+time=\\S+\\s+timezone=".
Available Plugin Fields
The following plugin fields are important attributes extracted from the syslog message. The USM Anywhere reports use these fields, and you can also reference them when creating custom reports. In addition to reporting, the USM Anywhere correlation rules make use of these fields.
Additional Resources and Troubleshooting
For troubleshooting, refer to the vendor documentation: