Add-on for Sophos XG - provides CIM compliance for the Network Sessions, Network Traffic, Intrusion Detection, Malware, Web and Authentication data models.
NEW: Ensure 'Central Reporting Format' is selected in the Sophos Log settings. This setting sets the ISO8601 Timestamp format and also provides some additional fields.
Use sourcetype: sophos:xg:syslog
Sophos log source documentation: https://docs.sophos.com/nsg/sophos-firewall/18.5/PDF/SF%20syslog%20guide%2018.5.pdf