[Filebeat] Add sophos XG log samples containing new field names#31038
[Filebeat] Add sophos XG log samples containing new field names#31038piellick wants to merge 2 commits intoelastic:mainfrom
Conversation
Here is a bunch of firewall logs from sophos.
|
💚 CLA has been signed |
|
This pull request does not have a backport label. Could you fix it @piellick? 🙏
NOTE: |
|
@piellick Thank you. Can you please sign the Contributor License Agreement (CLA). https://www.elastic.co/contributor-agreement |
|
What version of Sophos XG are these logs taken from? |
|
Pinging @elastic/security-external-integrations (Team:Security-External Integrations) |
|
Hi @andrewkroh
In meanwhile, i have found this doc who provide sample logs per log type fro 18.5.X version : |
|
Indeed, that is a great resource. Thanks |
|
Thanks for providing these @piellick. It looks like they have been retained in a quoted document (probably as a JSON string). Is that the case? |
|
Great. Thanks for confirming. I will go over it and fix up some of the issues that I noticed if that's OK with you, and generate the expected output so we can merge this. |
|
/test |
|
/test |
|
/test |
|
In elastic/integrations#3127 I incorporated the samples from the reference docs you pointed us to (thanks!). I didn't use the samples here b/c I think the documentation samples gives us good coverage. After the new version is out (#31388) if you still have issues let us know. I am curious if these samples came from the Sophos Log Viewer or were directly from a device over syslog? The reason I ask is because some of the fields, like |

Here is a bunch of firewall logs from sophos.
Type of change
Enhancement
What does this PR do?
Update firewall logs from sophos XG for testing.
Why is it important?
Related to PR #28932 --> [elastic/beats] [Filebeat] Sophos Module - support for changed field names