Sophos
Sophos is a log source template that enables you to fetch and normalize logs from Sophos security products, including Sophos Central and Sophos XG Firewall.
Enhancements
PLUG-12079
Added a
user field to SophosCompiledNormalizer output, extracted from the existing source field, to more clearly represent the person associated with an event. The existing source field is unchanged, so existing searches, dashboards, and alerts are not affected.
Sophos normalizers now support CompiledNormalizer Datetime Preference (CNDP), letting you configure the date format used to parse ambiguous datetime fields to match your environment.
Bug Fixes
PLUG-15827
The
log_ts field in SophosCentralCompiledNormalizer normalized logs was derived from the log collection time instead of the datetime value in the source log, because only the first ten characters of the datetime string were parsed and the field was typed as a string rather than a number. log_ts is now derived correctly from whichever of created_at or when is earliest in the raw log.
PLUG-15608
SophosXGFirewall system health logs were normalized with the
user field, which reports the percentage of CPU consumed by user-level processes, mapped in a way that could be mistaken for a username rather than a resource metric.
PLUG-12079
In SophosCompiledNormalizer, the value of the
message field was normalized under the name field instead. message is now normalized correctly. If you have searches, alerts, or dashboards built on the name field for this content, review and update them after upgrading.
Past Releases
Sophos v6.1.0 ▾
Enhancement
KB-22634
Added Syslog Collector based Sophos General log source template, simplifying the log source configuration process. To learn more, go to Creating Log Source via a Template.
Sophos v6.0.0 ▾
Enhancements
KB-20115
Added a new compiled normalizer SophosCompiledNormlaizer to support Sophos Central, Sophos Central CEF, Sophos EndPoint, Sophos EnterpriseConsoleServer, Sophos UTM and SophosXG Firewall logs.
KB-17554
Enhanced the performance of SophosXGFirewallCompiledNormalizer by reducing the time taken to normalizeSophosXG Firewall logs.
KB-16419
Added the device_category field in SophosXGFirewallCompiledNormalizer to forward SophosXGFirewalllogs to UEBA.
KB-18785
Replaced the recipient_count fieldwithreceiver_count in Sophos logs to maintain consistency. Also, updated signatures to normalize Sophos Email Appliance logs.
KB-18572
Added signatures in LP_Sophos UTM to normalizeSophos UTMlogs.
KB-20277
Renamed the inserted_ts field to insert_ts for SophosCompiledNormlaizer to normalize SophosEndPoint logs.
KB-20277
Replaced the Potential, Unwanted and Application labels with PUA label.
Bug Fix
KB-18373
SomeSophosXG Firewall logs were not properly normalized by SophosXGFirewallCompiledNormalizer.
Sophos v5.2.0 ▾
Enhancements
KB-15682
Renamed the event_name field to event to maintain consistency.
KB-13403
Added file, path, domain, compliance_status, application, object , and action fields in Sophos logs. Also, renamed object field to application to maintain consistency.
KB-13888
Removed the LP_Sophos UTM Policy Violation alert as it is no longer relevant.
KB-16876
Mapped the device_name, timestamp and device_name fields to device and device_model to host in SophosXGFirewallCompiledNormalizer.
KB-16876, KB-12943
Added signatures in LP_Sophos_XG_Firewall to normalize Sophos Firewall logs.
Bug Fixes
KB-17450
SophosCentralCEFCompiledNormalizer incorrectly normalized the value of severity.
KB-15474, KB-17037
Some Sophos Central logs were not properly normalized by SophosCentralCEFCompiledNormalizer.
KB-15570
Some Sophos UTM logs were not properly normalized by SophosUTMCompiledNormalizer.
Support
If you have any questions or require assistance, create a support ticket.
Comments
Article is closed for comments.
For Sophos_3.2.0.pak I can see for every dashboard, normalizsation package etc. the version number. Why not for Sophos_5.0.0.pak?
Sophos_5.0.0.pak contains a dashboard "Sophos UTM System" with version 36. But in the meantime exists a dashboard with version number 38 (SR #43051).