cancel
Showing results for 
Search instead for 
Did you mean: 
Highlighted

SIEM can't recognize logs from Sophos XG210

Jump to solution

I would like to ask if anyone successfully get logs from Sophos XG210. What's the Data Source Model and Data Format should be?

Now logs come into SIEM but as "Unknown" log.

 

Labels (1)
1 Solution

Accepted Solutions

Re: SIEM can't recognize logs from Sophos XG210

Jump to solution

I got adviced that you can use Cyberoam UTM and NGFW instead of Sophos/UTM & Next-Gen Firewall for XG210. I tested Cyberoam UTM can be recognized by SIEM, to be a temp solution.

Hope that help if you have same issue.

BRs,

Jim

1 Reply

Re: SIEM can't recognize logs from Sophos XG210

Jump to solution

I got adviced that you can use Cyberoam UTM and NGFW instead of Sophos/UTM & Next-Gen Firewall for XG210. I tested Cyberoam UTM can be recognized by SIEM, to be a temp solution.

Hope that help if you have same issue.

BRs,

Jim

ePO Support Center Plug-in
Check out the new ePO Support Center. Simply access the ePO Software Manager and follow the instructions in the Product Guide for the most commonly used utilities, top known issues announcements, search the knowledgebase for product documentation, and server status and statistics – all from within ePO.