UpPrevious Next
Sheriff CSM™
Sophos XG Firewall
When you configure Sophos XG Firewall to send log data to Sheriff CSM, you can use the Sophos XG plugin to translate raw log data into normalized events for analysis. The table below provides some basic information for the plugin:
Plugin Information
Device | Details |
Vendor | Sophos |
Device Type | Firewall |
Connection Type | Syslog |
Data Source Name | Sophos XG |
Data Source ID | 1747 |
Integrating Sophos XG
Before you configure the Sophos XG integration, you must have the IP Address of the Sheriff CSM Sensor (Deputy).
To configure Sophos XG to send log data to Sheriff CSM
- In the Sophos XG console, go to System > System Services > Log Settings and, under the Syslog Servers section, click Add.
-
Enter the server details:
Unless a specific device format is chosen, the device produces logs in its standard format.
Note: You can configure a maximum of five syslog servers.
- Click Save.
-
On System > System Services > Log Settings, enable all those logs that you want sent to the Sensor.
Plugin Enablement
For plugin enablement information, see
Enable Plugins.
Additional Resources and Troubleshooting
https://www.sophos.com/en-us/medialibrary/PDFs/documentation/Sophos-XG-Firewall-Administrator-Guide.pdf?la=en
For troubleshooting, refer to the vendor documentation:
https://community.sophos.com/kb?TopicId=10001