Configure Sophos XG Firewall to send logs to Arctic Wolf
You can configure the Sophos XG Firewall® to send the necessary logs to Arctic Wolf® for security monitoring.
These resources are required:
- An activated Capteur Arctic Wolf or Collecteur de journaux virtuel (vLC)
- Access to the Sophos Enterprise Console with administrator permissions
Note:
If the VPN Portal and SSL VPN service share the same WAN port, Sophos logs failed VPN login attempts from 127.0.0.1 instead of the real external IP address. For accurate source IP data, configure these services on separate ports, or remove WAN access from the service that does not need it.