Configure a Sophos UTM firewall to forward syslogs
- Navigate to Logging & Reporting > Log Settings > Remote Syslog Server
- On the Remote Syslog Server tab enable remote syslog.
- Click the toggle switch.
- Click the Plus icon in the Syslog Servers box to create a server.
- Name ActZero_Logging
- Click the + button next to the Server field
- In the edit network definition dialog box enter the following.
- Name ActZero_VM
- Type host
- IPv4 Address The local IP of the ActZero VM
- Click the Save button
- Click the Plus icon next to the port field
- In the Edit service definition dialog box enter the following.
- Name ActZero_syslog
- Type of definition UDP
- Destination Port 514
- Source Port 1:65535
- Comment remote udp syslog
- Format Device Standard Format
- Click the Save button
- Ensure the Remote Syslog Log Selection has Select All checkbox turned on.
Reference Sophos UTM documentation for further detail.
Was this documentation helpful? Please send us your feedback!