Skip to content

Latest commit

 

History

History
36 lines (29 loc) · 820 Bytes

f8556e2d-6721-4671-816d-4f59bf33da57.md

File metadata and controls

36 lines (29 loc) · 820 Bytes

Mappings: Sophos UTM 9 Firewall - Custom Parser

Input Requirements

Input Value
Vendor Sophos
Product UTM 9
Log Format JSON
Event ID Regex Pattern _default_

Record Output

Output Value
Vendor Sophos
Product UTM 9
Record Type Network

Fields Mapped

Cloud SIEM Schema Field Original Record Key Notes
action action
description name
device_hostname syslog_hostname
dstDevice_ip dstip
dstDevice_mac dstmac
dstPort dstport
ipProtocol proto This is a lookup field. More info to come in the catalog later...
severity severity
srcDevice_ip srcip
srcDevice_mac srcmac
srcPort srcport
success action This is a lookup field. More info to come in the catalog later...