elastic / integrations

Elastic Integrations
https://www.elastic.co/integrations
Other
28 stars 445 forks source link

Sophos UTM #6184

Closed jamiehynds closed 1 year ago

jamiehynds commented 1 year ago

Description

Sophos UTM is a unified threat management platform designed to protect your businesses from known and emerging malware including viruses, rootkits and spyware. The solution provides a complete network security package with everything your organization needs in a single modular appliance. Capabilities include Web and Email Filtering, Network Protection, Network Routing and Services, Advanced Threat Protection, Authentication, Email Encryption and DLP, Web Policy and VPN.

Architecture

Sophos provides a syslog output to transmit logs to a SIEM. As outlined in Sophos docs , there are several log categories available. Scope of this integration will be limited to dhcpd, http and packet filter based on customer supplied log samples.

This integration will provide an update to the current UTM and will replace the Javascript processing, in favor of ingest pipelines.

Integration release checklist

This checklist is intended for integrations maintainers to ensure consistency when creating or updating a Package, Module or Dataset for an Integration.

All changes

New Package

Dashboards changes

Log dataset changes

elasticmachine commented 1 year ago

Pinging @elastic/security-external-integrations (Team:Security-External Integrations)