This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Log analysis and warning

Hi,

Our company is using a XG firewall.

I can send the logs to a log management system (ELK) and break a log message into fields.

I can find the Firewall Log Format here: https://community.sophos.com/kb/en-us/130308

However, my security knowledge is limited.

Could you please help me to identify the important security messages from the logs ?

E.g. if Log subtype = Admin and Status = Failed (some one tried to log in the firewall with wrong password).

Thanks.



This thread was automatically locked due to age.