Skip to content

How to ingest and Process sophos Firewall logs #9202

Locked Answered by Rdago
brunbrun2 asked this question in Unsupported Versions
Discussion options

You must be logged in to vote

log_sources hostgroup seems to be missing.

Add log_sources to /opt/so/saltstack/local/salt/firewall/hostgroups.local.yaml and try again:

 firewall:
  hostgroups:
    log_sources:
      ips:
        delete: []
        insert: [127.0.0.1, X.X.X.X/24]

reference: https://docs.securityonion.net/en/2.3/firewall.html

Replies: 2 comments 2 replies

Comment options

You must be logged in to vote
1 reply
@brunbrun2
Comment options

Comment options

You must be logged in to vote
1 reply
@brunbrun2
Comment options

Answer selected by dougburks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants