The Sophos Firewall integration is available on our Enterprise and Advanced packages.
Before you get started
Before beginning the integration, you will need to deploy a log collector within the same network as your firewall.
To initiate the collector deployment process, please reach out to our Technical Support team, who'll provide you with a deployment pack that includes all the software and scripts needed to configure this.
If you already have a log collector deployed, please follow the steps outlined below.
Configuring your Sophos Firewall
Access the Sophos Firewall management console.
This can be done via Sophos Central and going to My Products > Firewall Management > Firewalls and selecting the Firewall you want to log to us.
Alternatively, you can access it via the Web Admin Console by entering the IP address of the Firewall into the search bar of your web browser and entering your administrator username and password.
Adding a Syslog Server.
Go to System services > Log settings and click Add.
Enter a name eg. Defense.com Collector.
Specify the settings:
IP address/domain: This should be the private IP of your log collector.
Secure log transmission: This should be turned Off.
Port: This should be port 5514.
Facility: This should be set to DAEMON.
Severity level: This should be set to Debug.
Format: This should be set to Standard Syslog Protocol.
Click Save.
Go to Log settings and select the logs you want to send to the syslog server.
Confirming log flow
Once the above steps are complete, your device will now ship logs to our SIEM platform via your collector. You can confirm logs are successfully reaching our SIEM by either.
Navigating to the Log Search feature in Defense.com by browsing to SIEM > Log Search and then filtering the logs by
type:"syslog".Reaching out to our Technical Support team, who'll be able to check and confirm this for you.
And that's it! You've successfully integrated your Sophos Firewall π
