DEV Community

Nguyen Dong
Nguyen Dong

Posted on

Sophos Firewall logs and Wazuh: the newer syslog layout matches no decoder

Sophos Firewall can send syslog in two layouts. Wazuh 4.14.7 reads one of them. If your firewall uses the other, the logs arrive and nothing alerts, ever. We measured both, and tested two fixes.

The two layouts

Sophos's own syslog guide documents both. The legacy one, which Sophos calls Device standard:

device="SFW" date=2018-05-30 time=13:14:26 timezone="IST" device_name="XG125w" device_id=SFDemo-763180a log_id=010102600002 log_type="Firewall" log_component="Firewall Rule" log_subtype="Denied" status="Deny" ...
Enter fullscreen mode Exit fullscreen mode

And Central reporting:

device_name="SFW" timestamp="2023-12-11T09:02:50-0500" device_model="SF01V" device_serial_id="SFDemo-c07-gl-vm-01" log_id="010101600001" log_type="Firewall" log_component="Firewall Rule" log_subtype="Allowed" ...
Enter fullscreen mode Exit fullscreen mode

What Wazuh does with each

The stock decoder in ruleset/decoders/0510-sophos_fw_decoders.xml is anchored on the legacy start of line:

<prematch>^device="\w*"\s+date=\d+-\d+-\d+\s+time=</prematch>
Enter fullscreen mode Exit fullscreen mode

We sent a denied-traffic line in each layout over UDP syslog to a Wazuh 4.14.7 manager:

Layout Result
legacy (device="SFW" date=…) decoded as sophos-fw → rule 70021, level 5, Traffic Denied
Central reporting (device_name="SFW" timestamp=…) No decoder matched → generic rule 1002, level 2 → no alert

The stock rules key on the decoded status field, and the Central reporting layout has no status at all; it carries log_subtype instead. So a Central reporting line has neither the decoder nor the field the rules need.

Fix 1: send the legacy layout

If your firewall's syslog server settings let you pick the format, choose the device-standard one and the stock decoder and rules apply unchanged. Check first whether anything else reading the same stream expects the new layout.

Fix 2: decode the Central reporting layout

A parent decoder anchored on the new start of line, then one child per field:

<decoder name="sophos-fw-crf">
  <prematch>^device_name="\S+" timestamp="</prematch>
</decoder>

<decoder name="sophos-fw-crf-fields">
  <parent>sophos-fw-crf</parent>
  <regex type="pcre2">log_type="([^"]*)" log_component="([^"]*)" log_subtype="([^"]*)"</regex>
  <order>log_type, log_component, log_subtype</order>
</decoder>

<decoder name="sophos-fw-crf-fields">
  <parent>sophos-fw-crf</parent>
  <regex type="pcre2">\bsrc_ip="([^"]*)"</regex>
  <order>srcip</order>
</decoder>
Enter fullscreen mode Exit fullscreen mode

(and the same pattern for dst_ip, src_port, dst_port, protocol, fw_rule_id). Rules on log_type = Firewall and log_subtype = Denied / Allowed, plus an 18-in-45-seconds rule with <same_source_ip />.

Writing the address as srcip (the stock decoder uses src_ip) matters: <same_source_ip> and the firewall-drop active response only read srcip.

What we measured with it on 4.14.7:

Sent Before After
1 Central reporting denied line 0 alerts level 5, srcip/dstip/dstport read
the same, 18 times in a few seconds no alert 17 × level 5, then the level 10 rule
Sophos's own Allowed example no decoder level 3
1 legacy denied line 70021 70021, untouched

wazuh-analysisd -t: no warnings.

Limits

Measured on a Wazuh 4.14.7 manager container with syslog over UDP and in wazuh-logtest. We did not run a Sophos Firewall. The Allowed line is Sophos's published example; the Denied lines were written by us in the same layout. The decoder covers firewall-rule events only, not admin login, IPS, web filter or VPN. We have not checked which SFOS release made Central reporting the default, or the exact menu name for the format setting.

The full decoder and rule files, with the one-minute checks: https://atkvn.com/fix-sophos-firewall-logs-not-showing-in-wazuh.html

Dong Nguyen, ATK New Technology. We check and fix Wazuh rules for people who run it.

Top comments (0)