Hi,
We have Sophos Enterprise Mangament Console v4.7, installed with Sophos Reporting Interface and Log Writer. Both are running smoothly and don't even have any issues.
Now, we have recently acquired a new SIEM solution which we can have all our server logs and all other stuff we can put into that solution. one of them is the sophos events. I know this is possible to integrate or send those sophos event log to a SIEM solution such as splunk.
My question is, how can we pull/push the sophos event logs to our SIEM solution. is it possible to send it via syslog? or is there any other way we can gather those logs to our SIEM solution in real time?
Appreciat on immediate feedback
Boodie
This thread was automatically locked due to age.