# Integration sophos Firewall with elastic

**URL:** <https://discuss.elastic.co/t/integration-sophos-firewall-with-elastic/329454>\
**Category:** SIEM\
**Created:** [April 5, 2023, 6:16pm UTC](https://discuss.elastic.co/t/integration-sophos-firewall-with-elastic/329454 "2023-04-05T18:16:29Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ahmad\_Shrateh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ahmad_shrateh/32/119476_2.png) [@Ahmad\_Shrateh](https://discuss.elastic.co/u/Ahmad_Shrateh)\
**Post date:** [April 5, 2023, 6:16pm UTC](https://discuss.elastic.co/t/integration-sophos-firewall-with-elastic/329454/1 "2023-04-05T18:16:29Z")

</div>

Dear there. Im trying to connect sophos firewall with elastic but i don't receive any logs.  
Im deployed an agent with sophos integration, and i followed the instructions on the elastic, i add my firewall ip instead localhost ( udp).what i should to do ?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [April 5, 2023, 7:36pm UTC](https://discuss.elastic.co/t/integration-sophos-firewall-with-elastic/329454/2 "2023-04-05T19:36:42Z")

</div>

> [@Ahmad\_Shrateh](#):
>
> i add my firewall ip instead localhost ( udp).what i should to do ?

Can you share how you configured it?

Normally on those integrations you add the IP address of the server running the Elastic Agent and it will listen on it, then you need to configure your Firewall device to send logs to this IP/Port.

This is mentioned in the [documentation](https://docs.elastic.co/integrations/sophos).

> To configure a remote syslog destination, please reference the [SophosXG/SFOS Documentation](https://community.sophos.com/kb/en-us/123184).

---

<div class="post-metadata">

**Author:** ![Ahmad\_Shrateh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ahmad_shrateh/32/119476_2.png) [@Ahmad\_Shrateh](https://discuss.elastic.co/u/Ahmad_Shrateh)\
**Post date:** [April 6, 2023, 6:46am UTC](https://discuss.elastic.co/t/integration-sophos-firewall-with-elastic/329454/3 "2023-04-06T06:46:08Z")

</div>

sopoh firewall : 192.186.1.20/ 514 ( the ip of my elastic agent)

sophos integration Via UDP:  
UDP host to listen on  
192.186.1.20  
UDP port to listen on  
9549  
syslogs host  
0.0.0.0  
9005

here is what im using

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [April 6, 2023, 12:33pm UTC](https://discuss.elastic.co/t/integration-sophos-firewall-with-elastic/329454/4 "2023-04-06T12:33:25Z")

</div>

If you configured the Elastic Agent to list on port `9549` you need to configure your Sophos firewall to send logs to the IP of the Elastic Agent on this port.

---

<div class="post-metadata">

**Author:** ![Ahmad\_Shrateh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ahmad_shrateh/32/119476_2.png) [@Ahmad\_Shrateh](https://discuss.elastic.co/u/Ahmad_Shrateh)\
**Post date:** [April 6, 2023, 8:59pm UTC](https://discuss.elastic.co/t/integration-sophos-firewall-with-elastic/329454/5 "2023-04-06T20:59:55Z")

</div>

Yeah, i understand that later . But what about the syslogs host ? Should i add the agent's ip with a different port?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [April 6, 2023, 10:14pm UTC](https://discuss.elastic.co/t/integration-sophos-firewall-with-elastic/329454/6 "2023-04-06T22:14:07Z")

</div>

What syslogs hosts? It is not clear what you are referring to.

The Sophos integration will only work for logs from Sophos firewall.

---

<div class="post-metadata">

**Author:** ![Ahmad\_Shrateh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ahmad_shrateh/32/119476_2.png) [@Ahmad\_Shrateh](https://discuss.elastic.co/u/Ahmad_Shrateh)\
**Post date:** [April 6, 2023, 10:33pm UTC](https://discuss.elastic.co/t/integration-sophos-firewall-with-elastic/329454/7 "2023-04-06T22:33:32Z")

</div>

There is a section that needs to be filled out .

 ![Screenshot_20230407_012958_Gallery](https://us1.discourse-cdn.com/elastic/original/3X/f/e/fe497e7303868e981590ea2f450612bcec3460b5.jpeg)

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [April 6, 2023, 11:08pm UTC](https://discuss.elastic.co/t/integration-sophos-firewall-with-elastic/329454/8 "2023-04-06T23:08:12Z")

</div>

This is where you need to put the IP of the Elastic Agent or use `0.0.0.0`

Same thing for the port, this is the port where the elastic agent will listen for the logs from your firewall.

---

<div class="post-metadata">

**Author:** ![Ahmad\_Shrateh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ahmad_shrateh/32/119476_2.png) [@Ahmad\_Shrateh](https://discuss.elastic.co/u/Ahmad_Shrateh)\
**Post date:** [April 9, 2023, 12:46pm UTC](https://discuss.elastic.co/t/integration-sophos-firewall-with-elastic/329454/9 "2023-04-09T12:46:01Z")

</div>

Not work!!

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/f/d/fd8b0bcbd45234842e804d1583b5928d23db2167.png)

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [April 9, 2023, 12:55pm UTC](https://discuss.elastic.co/t/integration-sophos-firewall-with-elastic/329454/10 "2023-04-09T12:55:10Z")

</div>

Is `10.1.0.117` the IP of your Agent? This need to be the IP of the Elastic Agen server or use `0.0.0.0`.

You can just use `0.0.0.0` , but the ports needs to be different, choose a different port for each one of those inputs, also, avoid using port `514` as this port is reserved for the `rsyslog` and you may already have a `rsyslog` running in the Elastic Agent Server.

On the Timezone Offset you need to remove the `local` word, look at the explanation, you need to set the timezone of your firewall in the `+HH:mm` format, so if your firewall has a timeoffset of 3 hours, you need to configure it in this format, `+03:00` or `-03:00`.

This is all the configuration you need to do on the Elastic Agent, everything else is in your Sophos, you need to configure it to send Sophos Logs to the UDP/port you configured and the XG Logs to the other UDP/port you configured, but how you do that needs to be validated on Sophos documentation.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [April 9, 2023, 1:17pm UTC](https://discuss.elastic.co/t/integration-sophos-firewall-with-elastic/329454/11 "2023-04-09T13:17:26Z")

</div>

I'm also not sure if you should use both _UTM_ and _XG Logs_, you would need to be able to configure in sophos to send those types of logs to different ports.

I would suggest that you configure it in steps, first configure the _UTM_ logs and see if you are receiving the logs, then check in Sophos if you can send the _XG Logs_ to a different port.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 7, 2023, 1:18pm UTC](https://discuss.elastic.co/t/integration-sophos-firewall-with-elastic/329454/12 "2023-05-07T13:18:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
