Logo
Resources
Documentation Portal Ideas Portal Guardsix Academy License Portal
Resources
Documentation Portal Ideas Portal Guardsix Academy License Portal
Sign in
  1. Guardsix Servicedesk
  2. Products Hub
  3. Marketplace

Sophos

Sophos is a log source template that enables you to fetch and normalize logs from Sophos security products, including Sophos Central and Sophos XG Firewall.

Release Details

Version: 6.3.0
Release date: August 05, 2026
Supported On: Logpoint v7.4.0 and later
SHA 256: 2b8ada587c4520bc52a9b256344896d38a4811fd37518e0a5c242b6adbc4f87e
Sophos user guide
Download

Enhancements

PLUG-12079
Added a user field to SophosCompiledNormalizer output, extracted from the existing source field, to more clearly represent the person associated with an event. The existing source field is unchanged, so existing searches, dashboards, and alerts are not affected.
Sophos normalizers now support CompiledNormalizer Datetime Preference (CNDP), letting you configure the date format used to parse ambiguous datetime fields to match your environment.

Bug Fixes

PLUG-15827
The log_ts field in SophosCentralCompiledNormalizer normalized logs was derived from the log collection time instead of the datetime value in the source log, because only the first ten characters of the datetime string were parsed and the field was typed as a string rather than a number. log_ts is now derived correctly from whichever of created_at or when is earliest in the raw log.
PLUG-15608
SophosXGFirewall system health logs were normalized with the user field, which reports the percentage of CPU consumed by user-level processes, mapped in a way that could be mistaken for a username rather than a resource metric.
PLUG-12079
In SophosCompiledNormalizer, the value of the message field was normalized under the name field instead. message is now normalized correctly. If you have searches, alerts, or dashboards built on the name field for this content, review and update them after upgrading.

Past Releases

Sophos v6.1.0 ▾
Version: 6.1.0
Supported On: Logpoint v7.4.0 or later
SHA 256: 964ef19f6c59be0cabd41e6b57790a45bb5148685790ef40011aec52dfb90eb4
Download

Enhancement

KB-22634
Added Syslog Collector based Sophos General log source template, simplifying the log source configuration process. To learn more, go to Creating Log Source via a Template.
Sophos v6.0.0 ▾
Version: 6.0.0
Release date: August 08, 2023
Supported On: Logpoint v6.7.0 and later
SHA 256: 43af7924dd34d658ec895712d3e5dc65de10dddd40c54576ab9a418e296c9ae4
Download

Enhancements

KB-20115
Added a new compiled normalizer SophosCompiledNormlaizer to support Sophos Central, Sophos Central CEF, Sophos EndPoint, Sophos EnterpriseConsoleServer, Sophos UTM and SophosXG Firewall logs. 
KB-17554
Enhanced the performance of SophosXGFirewallCompiledNormalizer by reducing the time taken to normalizeSophosXG Firewall logs.
KB-16419
Added the device_category field in SophosXGFirewallCompiledNormalizer to forward SophosXGFirewalllogs to UEBA.
KB-18785
Replaced the recipient_count fieldwithreceiver_count in Sophos logs to maintain consistency. Also, updated signatures to normalize Sophos Email Appliance logs. 
KB-18572
Added signatures in LP_Sophos UTM to normalizeSophos UTMlogs. 
KB-20277
Renamed the inserted_ts field to insert_ts for SophosCompiledNormlaizer to normalize SophosEndPoint logs.
KB-20277
Replaced the Potential, Unwanted and Application labels with PUA label. 

Bug Fix

KB-18373
SomeSophosXG Firewall logs were not properly normalized by SophosXGFirewallCompiledNormalizer.
Sophos v5.2.0 ▾
Version: 5.2.0
Release date: October 20, 2022
Supported On: Logpoint v6.7.0 and later
SHA 256: 5701dfff24a00365648be97d0766ec91f15eede8b42b5b31344771539b3c27cb
Download

Enhancements

KB-15682
Renamed the event_name field to event to maintain consistency.
KB-13403
Added file, path, domain, compliance_status, application, object , and action fields in Sophos logs. Also, renamed object field to application to maintain consistency.
KB-13888
Removed the LP_Sophos UTM Policy Violation alert as it is no longer relevant.
KB-16876
Mapped the device_name, timestamp and device_name fields to device and device_model to host in SophosXGFirewallCompiledNormalizer. 
KB-16876, KB-12943
Added signatures in LP_Sophos_XG_Firewall  to normalize Sophos Firewall logs. 

Bug Fixes

KB-17450
SophosCentralCEFCompiledNormalizer incorrectly normalized the value of severity.
KB-15474, KB-17037
Some Sophos Central logs were not properly normalized by SophosCentralCEFCompiledNormalizer.
KB-15570
Some Sophos UTM logs were not properly normalized by SophosUTMCompiledNormalizer.

Support

If you have any questions or require assistance, create a support ticket.

Comments

  • Avatar
    Hans Vedder
    February 27, 2020 14:59

    For Sophos_3.2.0.pak I can see for every dashboard, normalizsation package etc. the version number. Why not for Sophos_5.0.0.pak?

    Sophos_5.0.0.pak contains a dashboard "Sophos UTM System" with version 36. But in the meantime exists a dashboard with version number 38 (SR #43051).

    Comment actions Permalink

Article is closed for comments.

Follow

Related articles

  • Universal REST API Fetcher
  • AWSServices
  • Creation of a new normalization request
  • Universal Normalizer
  • Thycotic
Consent Required To Proceed
By clicking “I Agree & Download”, you confirm that you are authorized to act on behalf of your organization and you give explicit consent for Guardsix to share your organization’s customer name and log source count with NXLog for the sole purposes of entitlement management, compliance verification, and support delivery related to the embedded NXLog technology in the Guardsix SIEM solution.

This data will not be used for sales or marketing and will not be shared with other third parties. You may withdraw your consent at any time by contacting Guardsix Support; withdrawal will not affect processing already performed.
Cancel I Agree & Download
Privacy policy    EULA    Terms of service   
Copyright © , Guardsix. All rights reserved.

Note: We use cookies that are essential for the smooth functioning of our website.