This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Reading ESA Message Log

Hi All,

I am having some issues parsing the logs from the appliance i've got the majority off them sorted, its just the Message log I am having issues with.

Can anyone point me in the direction of a document or let me know what the fields are in log entries?

http://esa.sophos.com/docs/esa/webhelp/index.html#sea/references/SEASyslog.html

shows examples, but unlike the equivalent one for the Web appliance, (http://wsa.sophos.com/docs/wsa/webhelp/index.html#swa/concepts/InterpretingLogFiles.html)

it doesnt give you the key to the logs

I am trying to get them normalised so i can pass them into our SIEM, I can make educated guesses, but

"p=0.151 fur=150.70.236.149 r=155.231.210.253 tm=0.23 a=d/eom" means little to me



This thread was automatically locked due to age.