Hello All,
I am trying to export all data/events to SIEM i.e Qradar, however the event collector unable to pull data from Sophos somehow. I tried with following configuration in Qradar:
Log Source Type: Sophos Enterprise Console
Protocol Type: Sophos Enterprise Console JDBC
Log Source Identifier: SOPHOS552
Database Type: MSDE
Database Name: SOPHOS552
IP or Hostname: x.x.x.x
Port: 1168
Username: xyz
Table Name: vEventsCommonData
Select List: *
Compare Field: InsertedAt
Do we need to configure anything at Sophos end? any suggestions ?
This thread was automatically locked due to age.