Apr 26 2023 07:29 AM
Hello.
I'm trying with fail to connect the Sophos XG data connector to Sentinel. I have used the KQL parser and followed all steps to the on the documentation but still can seem to get it working. For more context I'm trying to proxy via Syslog on Azure.
Facility= daemon
TLS =Enabled
Apr 26 2023 08:27 AM
Do you have an error, or just no data in the Syslog table?
Did you use the latest version in the [Content Hub]?
Is the connector Installed and Connected (green)?
Apr 26 2023 08:35 AM
Apr 26 2023 08:51 AM
Apr 27 2023 01:57 AM
Apr 27 2023 02:05 AM
@Tshepang5499 In that case, working on the Parser wont help - its looking more like Sophos XG or more likely the Log Forwarder isn't sending the Syslog data to Sentinel yet.