Closed leehinman closed 2 years ago
Pinging @elastic/security-external-integrations (Team:Security-External Integrations)
See elastic/integrations#2158 and elastic/integrations#2163 for the agent integration.
We have log samples in both https://github.com/elastic/beats/pull/31038 and https://github.com/elastic/integrations/pull/2163. I think the updated pipeline should handle both the old and new log format to have broader Sophos XG version compatibility.
There are fixes in both https://github.com/elastic/integrations/pull/2163 and https://github.com/elastic/beats/pull/28932. I think we should finish the elastic/integrations PR and then sync the whole pipeline back into the Filebeat module.
hello guys,
In meanwhile, i have found this doc who provide sample logs per log type fro 18.5.X version : [https://docs.sophos.com/nsg/sophos-firewall/18.5/PDF/SF%20syslog%20guide%2018.5.pdf] Could be very helpfull for you.
device_serial_id
as alternate fordevice_id
dst_zone_type
as alternate fordstzonetype
src_zone_type
as alternate forsrczonetype
srczone
andstzone
as custom fields