Hi All,
I am having some issues parsing the logs from the appliance i've got the majority off them sorted, its just the Message log I am having issues with.
Can anyone point me in the direction of a document or let me know what the fields are in log entries?
http://esa.sophos.com/docs/esa/webhelp/index.html#sea/references/SEASyslog.html
shows examples, but unlike the equivalent one for the Web appliance, (http://wsa.sophos.com/docs/wsa/webhelp/index.html#swa/concepts/InterpretingLogFiles.html)
it doesnt give you the key to the logs
I am trying to get them normalised so i can pass them into our SIEM, I can make educated guesses, but
"p=0.151 fur=150.70.236.149 r=155.231.210.253 tm=0.23 a=d/eom" means little to me
This thread was automatically locked due to age.