sophos/Sophos-Central-SIEM-Integration
Simple integration script for 3rd party systems such as SIEMs. Offers command line, file or syslog output in CEF, JSON or key-value pair formats.
Python
Issues
- 1
errors when running siem.py script
#88 opened by dianabogdan - 0
- 2
Include audit into downloaded events
#74 opened by backloop-biz - 0
- 8
Remove the facility number on TCP
#81 opened by paminhoff - 0
Facility Number
#90 opened by knumbness - 0
- 0
Siem event and alert log collect not work
#86 opened by Sue1990 - 0
- 2
the script pull the logs to the local server but not send them to my siem collector
#82 opened by ithamar21 - 1
Insufficient Logging from tool
#83 opened by marinhms - 0
- 1
2.1.0 siem.py -v still reports as 2.0.1
#75 opened by rave-net - 1
Using environment vars in config.ini
#71 opened by KrisMacBP - 6
Missing Events
#53 opened by gautaus - 0
- 9
- 1
Script not respecting state file
#66 opened by ecollins-sophos - 3
Cannot convert dhost into CEF format
#18 opened by abunn-r7 - 1
Category in web filter bypass
#39 opened by davidrudduck - 0
Severity Map
#58 opened by cbxsec1 - 3
syslog export to siem
#47 opened by Ari-R - 7
Thousands of duplicate events
#50 opened by apreheim - 4
- 1
Multi Tenant support
#62 opened by Vetpeet - 3
JSON Result File contains empty lines
#37 opened by matthewtckr - 8
No JSON object could be decoded
#31 opened by Balackie - 2
Error trying to run siem.py
#34 opened by vladimirgluten - 2
Different "state_file_name"
#22 opened by AndreaErrani - 1
- 2
REQUEST - Customer Name Field
#14 opened by arnydo - 1
Add Tag for Customer
#38 opened by taycom - 4
API return just 100 random endpoints
#23 opened by saostad - 2
- 5
syslog export for rapid7
#44 opened by ethernetguru - 5
Issue running into RHEAL 7
#55 opened by kaaltech - 1
Multiple API configuration in Script
#54 opened by arjamb - 1
Sub Estate
#24 opened by xayleth - 1
Multi-Tenancy Support
#41 opened by davidrudduck - 2
Sophos Partner API Integration
#36 opened by UMB-Linus - 2
Support python 3
#35 opened - 8
Error running siem.py (invalid syntax)
#48 opened by syunusic - 1
Siem.py doesnt forward events to Syslog
#45 opened by WinterIsCommin - 1
- 7
No section: 'login'
#16 opened by dannyhanes - 3
python siem.py fails wirth "AttributeError: 'NoneType' object has no attribute 'group'"
#20 opened by DavidRHawley - 3
JSON object must be str, not 'bytes'
#12 opened by runtman - 0
KeyValue formats are not consistant
#17 opened by thepcn3rd - 1
Internal Server Error
#15 opened by Mogibear - 1
Duplicate alerts are getting logged in "endpoint = all" configuration in config.ini
#10 opened by rakeshajmera