How to ingest and Process sophos Firewall logs #9202
-
Dear all, Second move
then there's an error: local:
|
Beta Was this translation helpful? Give feedback.
Replies: 2 comments 2 replies
-
Anybody can't help me? |
Beta Was this translation helpful? Give feedback.
-
Add log_sources to
reference: https://docs.securityonion.net/en/2.3/firewall.html |
Beta Was this translation helpful? Give feedback.
log_sources
hostgroup seems to be missing.Add log_sources to
/opt/so/saltstack/local/salt/firewall/hostgroups.local.yaml
and try again:reference: https://docs.securityonion.net/en/2.3/firewall.html