-
Notifications
You must be signed in to change notification settings - Fork 4.9k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[Filebeat] Add sophos XG log samples containing new field names #31038
Conversation
Here is a bunch of firewall logs from sophos.
💚 CLA has been signed |
This pull request does not have a backport label. Could you fix it @piellick? 🙏
NOTE: |
@piellick Thank you. Can you please sign the Contributor License Agreement (CLA). https://www.elastic.co/contributor-agreement |
What version of Sophos XG are these logs taken from? |
Pinging @elastic/security-external-integrations (Team:Security-External Integrations) |
Hi @andrewkroh
In meanwhile, i have found this doc who provide sample logs per log type fro 18.5.X version : |
Indeed, that is a great resource. Thanks |
Thanks for providing these @piellick. It looks like they have been retained in a quoted document (probably as a JSON string). Is that the case? |
Great. Thanks for confirming. I will go over it and fix up some of the issues that I noticed if that's OK with you, and generate the expected output so we can merge this. |
/test |
/test |
/test |
In elastic/integrations#3127 I incorporated the samples from the reference docs you pointed us to (thanks!). I didn't use the samples here b/c I think the documentation samples gives us good coverage. After the new version is out (#31388) if you still have issues let us know. I am curious if these samples came from the Sophos Log Viewer or were directly from a device over syslog? The reason I ask is because some of the fields, like |
Here is a bunch of firewall logs from sophos.
Type of change
Enhancement
What does this PR do?
Update firewall logs from sophos XG for testing.
Why is it important?
Related to PR #28932 --> [elastic/beats] [Filebeat] Sophos Module - support for changed field names