Configure Sophos Enterprise Console to send logs to Arctic Wolf
You can configure your Sophos Enterprise Console® to send the necessary logs to Arctic Wolf® for security monitoring.
Note:
- This product was retired on 20 July 2023. For more information, see the Sophos Enterprise Console® notice.
- This syslog configuration is for the on-premises Sophos Enterprise Console. For the cloud configuration, see Configure Sophos Central for Arctic Wolf monitoring using OAuth2 .
These resources are required:
- An activated Arctic Wolf Sensor or Virtual Log Collector (vLC)
- Access to the Sophos Enterprise Console with administrator permissions
These actions are required:
- If you use role-based administration:
- Make sure that you have Policy setting - anti-virus and HIPS permissions.
- You cannot edit a policy if it is applied outside your active Sub-Estate.
Enable syslog forwarding
- Sign in to the Sophos Enterprise Console as an administrator.
- Click the Policies tab.
- Double-click the anti-virus and host intrusion prevention system (HIPS) policy that you want to change.
- Click Messaging.
- Click the Event log tab.
- Select the Enable event logging option.
Install the Reporting Log Writer
Install NXLog
- Install NXLog.
- Contact your Concierge Security® Team (CST) for custom configuration.