cancel
Showing results for 
Search instead for 
Did you mean: 

SIEM can't recognize logs from Sophos XG210

Jump to solution

I would like to ask if anyone successfully get logs from Sophos XG210. What's the Data Source Model and Data Format should be?

Now logs come into SIEM but as "Unknown" log.

 

Labels (1)
1 Solution

Accepted Solutions

Re: SIEM can't recognize logs from Sophos XG210

Jump to solution

I got adviced that you can use Cyberoam UTM and NGFW instead of Sophos/UTM & Next-Gen Firewall for XG210. I tested Cyberoam UTM can be recognized by SIEM, to be a temp solution.

Hope that help if you have same issue.

BRs,

Jim

1 Reply

Re: SIEM can't recognize logs from Sophos XG210

Jump to solution

I got adviced that you can use Cyberoam UTM and NGFW instead of Sophos/UTM & Next-Gen Firewall for XG210. I tested Cyberoam UTM can be recognized by SIEM, to be a temp solution.

Hope that help if you have same issue.

BRs,

Jim

More McAfee Tools to Help You
  • Subscription Service Notification (SNS)
  • How-to: Endpoint Removal Tool
  • Support: Endpoint Security
  • eSupport: Policy Orchestrator