Hello everyone, longtime user of Astaro, Sophos UTM, and now XG. I wanted to get my XG working with an ELK stack. It was not as straightforward as I had hoped. It required multiple tweaks to index templates and logstash configurations to compensate for some of the XG syslog nuisances. Since it took me a while to get this working, I'd figured I'd share out what I did to get Sophos XG working with an ELK stack. Enjoy!
https://github.com/enigy/SophosXG-ELK
This thread was automatically locked due to age.