I wanna share the log files with a remote log server via one of my local LAN interfaces on S2S VPN, but the problem is my logs are being sent over my public IP address, how can i force Sophos to send my logs via Lan interface on S2S.
I'am trying to send logs to an external Syslog server via Remote Syslog Settings but i don't have any access to the server how am i gonna check if the logs are actually being sent?
Hallo zusammen, wir möchten gerne per Syslog die Daten an einen zentralen Syslogserver übertragen und auswerten. Gib es dazu eine Dokumentation über die einzelnen Syslogfelder und deren Bedeutungen (ähnlich wie bei der XG) ?
Gruß Stefan
Intermittently my UTM 9.7 stops sending logs to Fastvue Reported for Sophos listening on syslog port 514. Turning remote syslog on/off doesn't fix it, nor does rebooting - at either end (Sophos or Fastvue). I tried re-adding the source in Fastvue, which…
Came across a interesting issue when specifying the outbound interface to internal network for SNMP Traps, SMTP and SYSLOG they would still come out over the external interface. Searched for hours on the forums without much luck.
This was seemingly…
Hi,
I have a lot to do with Azure and I'd like to write the syslog of my UTM at home in my private OMS Log Analytics. ( https://azure.microsoft.com/en-us/services/log-analytics/ )
I'm a little surprised that I have not found any information on the…
Hallo Zusammen,
ich bin gerade dabei, das Remote-Logging mithilfe von Splunk zu testen. Hierfür benutze ich folgende Konfiguration auf der Sophos UTM:
(Der Server ist mit TCP-Port 5600 konfiguriert)
Es werden nur die Logs der Firewall an den…
Hello forum,
I'm looking for any whitepapers/recommendations available about configuring the logging. I know the basics but some more fine tune required. As of now on one of my UTM servers are ~3.500 users connected and generates http log in size of…
Sophos UTM 9 on AWS
Firmware: 9.408-4
I'm not seeing any options for encrypted SYSLOG - is this still not possible?
I did see this post from a few years ago in which the advice is to raise it as a feature request.
I understand that I can send…
I just stood up a UTM 9 instance at my house. I've got several kids with numbers mobile devices. What's the best solution for monitoring web traffic and reporting on it?
I'm interested in reporting based on user. User definitions will have to be MAC…
I installed iView hoping it would give better insight into how the users are accessing our sites. I can see number of hits for the "Real Web Server", but I can't see what external URL they are using or what IP address they are coming from. The user list…
Hi,
I configured the syslog server to send the Firewall log data to a server on udp port 514.
Using Kiwi Syslog Server to capture the data.
I could not see any data arriving, so i installed wireshark to check the traffic. Wireshark shows no traffic…
Posting this here if anyone wants to point their UTM logs to a remote logstash/elasticsearch instance. This is a working sample logstash.conf file.
I pointed my remote logging to my logstash server on port 5140. This works for all of the UTM log types…