cancel
Showing results for 
Search instead for 
Did you mean: 
Highlighted

SIEM can't recognize logs from Sophos XG210

Jump to solution

I would like to ask if anyone successfully get logs from Sophos XG210. What's the Data Source Model and Data Format should be?

Now logs come into SIEM but as "Unknown" log.

 

Labels (1)
1 Solution

Accepted Solutions

Re: SIEM can't recognize logs from Sophos XG210

Jump to solution

I got adviced that you can use Cyberoam UTM and NGFW instead of Sophos/UTM & Next-Gen Firewall for XG210. I tested Cyberoam UTM can be recognized by SIEM, to be a temp solution.

Hope that help if you have same issue.

BRs,

Jim

1 Reply

Re: SIEM can't recognize logs from Sophos XG210

Jump to solution

I got adviced that you can use Cyberoam UTM and NGFW instead of Sophos/UTM & Next-Gen Firewall for XG210. I tested Cyberoam UTM can be recognized by SIEM, to be a temp solution.

Hope that help if you have same issue.

BRs,

Jim

More McAfee Tools to Help You
  • How-to: Endpoint Removal Tool
  • Support: Endpoint Security
  • Visit: Business Service Portal
  • More: Search Knowledge Articles
  • ePolicy Orchestrator Support
  • The McAfee ePO Support Center Plug-in is now available in the Software Manager. Follow the instructions in the Product Guide for more.