This article provides instruction on how to setup and enable syslog forwarding on a Sophos firewall
Configure Syslog Server
- Navigate to System Services > Log Settings and click Add to configure a syslog server.
- Enter a Name for the syslog server.
- Enter the IP Address of the syslog server.
- Enter a Port number that the device will use for communicating with the syslog server. (UDP / 514 is recommended)
- Select the Facility option and choose the value DAEMON.
- Select the Severity Level from the available options and choose the value Information.
- The log format to be selected is Device Standard Format.
- Click Save the configuration.
Once you have added the server, go to the System > System Services > Log Settings page and enable all those logs, which are to be sent to the syslog server in the section Log Settings.
Enable Traffic Logging
- Enable firewall traffic logs:
- Go to Firewall > Edit Firewall Rule to view the status of logging and security policies.
- Enable logging of firewall traffic from Log Traffic section. It ensures that traffic passing through the Firewall rule has been logged and can be viewed from Log Viewer.
- Apply Security Policies
Set security policies to Allow All or Default Policies or a custom policy so that logs are generated. If the security policies are set to None then logs may not generate.
- Enable Logging
Go to Configure > System Services > Log Settings and select the checkbox Log Type (System) to enable logging for the Syslog server created in step 1. We recommend you enable logging for all security related modules, firewall rules and logon activities.
You've now setup syslog remote logging on your firewall. You are now ready to send firewall data to the RocketCyber firewall log analyzer. See related article to configure RocketCyber's firewall log analyzer, for receiving the data.