Mappings: Sophos UTM 9 Firewall - Custom Parser
Input | Value |
---|---|
Vendor | Sophos |
Product | UTM 9 |
Log Format | JSON |
Event ID Regex Pattern | _default_ |
Output | Value |
---|---|
Vendor | Sophos |
Product | UTM 9 |
Record Type | Network |
Cloud SIEM Schema Field | Original Record Key | Notes |
---|---|---|
action | action | |
description | name | |
device_hostname | syslog_hostname | |
dstDevice_ip | dstip | |
dstDevice_mac | dstmac | |
dstPort | dstport | |
ipProtocol | proto | This is a lookup field. More info to come in the catalog later... |
severity | severity | |
srcDevice_ip | srcip | |
srcDevice_mac | srcmac | |
srcPort | srcport | |
success | action | This is a lookup field. More info to come in the catalog later... |