Configure a Sophos XG firewall to forward syslogs
- Navigate to System Services > Log Settings
- click Add and input or select the following values:
- Name ActZero_Logging
- IP Address The local IP of the ActZero VM
- Port 514
- Facility LOCAL7
- Severity level INFO
- Format Device Standard Format
- Click Save.
Update all policies to log events.
- Navigate to Firewall > Edit Firewall Rule
- Ensure the Log Firewall Traffic checkbox is on for every rule.
Reference Sophos XG documentation for further detail.
Was this documentation helpful? Please send us your feedback!