This repository contains a custom JSON Graylog extractor for Sophos XG syslog. The code inspiration for this extractor was taken from zildjian4life218/Sophos-XG-Extractor as the starting point to understand the extractor code.
For detailed information on Sophos XG Syslog, refer to the SFOS Syslog Documentation.
The extractor has been tested and confirmed to work with logs available in the following environment: