Skip to content

Migrating from log collectors to XDR data collectors

As part of the migration to Sophos XDR, your existing Sophos Security Virtual Appliance (SVA) log collectors are being migrated to Sophos XDR data collectors.

The migration process automatically provisions a new Sophos XDR data collector for each of your SVAs. The new data collector is created with the settings from your existing SVA log collectors, including:

  • Collector name and hostname
  • Network configuration (IP address, subnet mask, gateway, DNS for static configurations, DHCP for dynamic configurations)
  • Syslog port and protocol settings from your SVA integrations

The provisioning of your new data collector is automatic, but deploying and activating it requires action on your end. This guide explains the deployment process and what to expect for each collector type and network configuration.

This table provides a high-level overview of the migration process. Continue reading below for more in-depth information.

Scenario IP address behavior Can run both data collectors? Data source update required?
On-Prem, Static IP (keep same IP) Same IP address as old SVA log collector. No. Power off old SVA log collector first. No
On-Prem, Static IP (change IP) Different IP address (chosen before ISO). Yes Yes
On-Prem, DHCP (default) Different IP address from DHCP. Yes Yes
On-Prem, DHCP (with reservation) Same IP address via DHCP reservation. No. Power off old SVA log collector first. No
Cloud (AWS / Azure / GCP) Always different IP address. Yes Yes

Why migrate?

Sophos XDR data collectors replace Sophos SVA log collectors with a simpler, more capable collection platform. Here are some of the benefits of migrating to XDR data collectors:

  • No more port mapping or firewall changes: XDR data collectors use outbound HTTPS connections to send data, eliminating the need to open inbound firewall ports or manage complex port-forwarding rules on your network.
  • Your configuration is migrated for you: We automatically carry over your collector name, network settings, and syslog port/protocol mappings so you don't have to rebuild your collector configuration from scratch.
  • Unified management in Sophos XDR: Manage all of your data collectors from a single console alongside your other Sophos XDR integrations.

Sophos XDR data collector types

Your SVA log collector platform determines which type of Sophos XDR data collector is created. Refer to the appropriate XDR data collector documentation for details on each collector type:

SVA Platform XDR data collector type Documentation
AWS Cloud AWS data collector
Azure Cloud Azure data collector
Google Cloud Cloud GCP data collector
VMware / Hyper-V / Nutanix On-Premises On-premises data collector

For information about what is and isn't included in this migration, see What is and isn't migrated.

IP address considerations

The most important factor in your migration is whether the new Sophos XDR data collector will use the same or a different IP address than your old SVA log collector. This determines whether you need to update the devices that send log data to the data collector.

On-premises data collectors with static IP

The new Sophos XDR data collector is provisioned with the same static IP address as your existing SVA log collector.

Because both collectors share the same IP address, you must power off the old SVA log collector before booting the new Sophos XDR data collector. Running both at the same time will cause an IP address conflict on your network. To make this cutover, do as follows:

  1. Power off the old Sophos SVA log collector.
  2. Deploy and boot the new Sophos XDR data collector. See On-premises data collector for installation instructions.
  3. In Sophos XDR, go to Security Operations > Integrations > Data Collectors to verify that the new data collector is online.

No data source changes are needed. Your devices will continue sending logs to the same IP address.

Can I run both collectors simultaneously?

If you prefer a gradual cutover where both the old SVA log collector and the new Sophos XDR data collector run simultaneously, you can change the IP address of the new data collector before downloading the ISO from Sophos XDR. This gives the new data collector a different IP, allowing both to coexist on the network. However, you'll then need to update your data sources to point to the new IP address. For more information, see Updating data sources.

On-premises data collectors with DHCP

The new Sophos XDR data collector will receive a new IP address from your DHCP server, so there's no risk of an IP conflict with the old SVA log collector. Both collectors can run simultaneously.

Since the IP address will be different, you'll need to update your data sources to send log data to the new data collector's IP address. For more information, see Updating data sources.

Can I use the same IP address for the old SVA log collector and the new data collector?

If you want the new Sophos XDR data collector to use the same IP address as your old SVA, do as follows:

  1. Create a DHCP reservation on your DHCP server for the new data collector's MAC address, assigning it the old SVA log collector's IP address.
  2. Power off the old SVA log collector so the reserved IP address becomes available.
  3. Boot the new Sophos XDR data collector. It'll receive the reserved IP.

No data source changes are needed since the IP address is the same.

Cloud-hosted data collectors (AWS, Azure, GCP)

For cloud-hosted data collectors, the migrated Sophos XDR data collector will always have a different IP address than the old SVA log collector. There's no IP conflict, and both data collectors can run simultaneously.

You'll need to update your data sources to point to the new data collector's IP address or DNS name. For more information, see Updating data sources.

Note about AWS

If you're using the CloudFormation template, the CTPxCollectorDnsName template output provides the DNS name for your syslog devices. Using this DNS name instead of a static IP simplifies future changes. For more information, see CloudFormation template.

Updating data sources

If the new Sophos XDR data collector has a different IP address from your old SVA log collector, all devices and applications that forward syslog data must be reconfigured to send to the new address.

Only the destination IP address or hostname needs to be updated on your log sources.

Syslog ports and protocols are preserved from your original SVA log collector's configuration. For example, if a device was sending logs via UDP on port 514, it'll continue to use UDP/514 on the new XDR data collector.

Finding your new XDR data collector's IP address

Consult this table to find your new data collector's address, depending on the collector type:

Data collector type Where to find the IP address
On-prem (static IP) This is the IP address that you configured when provisioning the data collector in Sophos XDR.
On-prem (DHCP) Check your DHCP server's lease table for the new VM's MAC address, or look up the data collector in Sophos XDR under Security Operations > Integrations > Data Collectors.
AWS Use the CTPxCollectorDnsName output from your CloudFormation stack. This is a DNS name (not an IP) provided by the Network Load Balancer. Find it in the AWS CloudFormation console under your stack's Outputs tab. Using this DNS name is recommended over a static IP.
Azure Check the VM's assigned IP address in the Azure portal under the VM's network interface settings, or look up the data collector in Sophos XDR under Security Operations > Integrations > Data Collectors.
GCP Check the compute instance's internal IP in the GCP console under Compute Engine > VM instances, or look up the data in Sophos XDR under Security Operations > Integrations > Data Collectors.

What is and isn't migrated

This section outlines which log collectors are part of this migration.

Migrated automatically

The migration service carries over the following from your Sophos SVA log collector:

Setting Details
Name The SVA log collector name becomes the XDR data collector name
Hostname Preserved from the SVA log collector (or derived from the name if not set)
Network configuration IP address, subnet mask, gateway, and DNS servers (for static); DHCP flag (for dynamic)
Syslog ports and protocols Port redirects are created to match your SVA log collector integrations. Source ports are preserved and mapped to standard syslog ports (UDP/514, TCP/601).
Collector type Cloud or On-Premises, based on the SVA log collector's platform

Not migrated

The following aren't carried over and may require manual configuration:

  • NDR integrations: NDR does not use syslog forwarding and isn't part of this migration. SVA log collectors with only NDR integrations (no syslog integrations) won’t have a corresponding Sophos XDR data collector created. If an SVA has a mix of NDR and syslog integrations, only the syslog integrations are migrated.
  • Event type filters: Any per-integration event type selections from the SVA log collector.
  • Exclusion lists: Domain and protocol exclusion lists configured on SVA integrations.
  • Syslog format and passthrough settings: SVA-specific syslog format configurations.
  • Credentials: Integration credentials aren't transferred.
  • Investigation consoles and Nessus scanners: Only SVA log collectors are migrated; other VM types are excluded.
  • Hardware appliances: Physical devices can't be migrated to virtual collectors.

Possible migration errors

Not every Sophos SVA log collector will have a corresponding Sophos XDR data collector created. The migration service validates each SVA log collector and skips those that can't be migrated. If any of your SVA log collectors fall into the categories below, they'll appear in the migration results as skipped or misconfigured.

Reason What it means What to do
Hardware appliance Physical hardware devices can't be migrated to virtual data collectors. Deploy a new Sophos XDR data collector manually to replace the hardware appliance.
Non-SVA virtual Investigation consoles, Nessus scanners, and other non-log collector VM types are excluded. These aren't log collectors and do not require migration.
NDR-only SVA SVA log collectors that have only NDR integrations and no syslog integrations. NDR does not use syslog forwarding. NDR is handled separately. No action needed for this migration.
No syslog integrations The SVA log collector has no configured syslog integrations (no port/protocol defined for any integration). If the SVA log collector is actively in use, verify its configuration in Sophos Fusion and contact support.
Invalid or incomplete network configuration For SVA log collectors with static IP addressing, the migration validates the IP address, subnet mask, gateway, and DNS servers. If any of these fields are missing or contain invalid values (for example, a malformed IP address or an invalid subnet mask), the SVA can't be migrated automatically. Correct the network configuration in Sophos Fusion and contact support to re-trigger migration, or deploy a new Sophos XDR data collector manually with the correct settings.

Tip

If you believe an SVA log collector should have been migrated but wasn't, check the SVA's configuration in the Sophos console for missing or invalid network fields. Common issues include blank gateway or DNS fields on statically-configured SVAs.

Data continuity during migration

Your existing Sophos log collectors continue to operate normally throughout the migration period. Here's what that means for your data:

  • No data gap: Your current SVA log collectors continue collecting and forwarding log data while you plan and execute the cutover to XDR data collectors. There's no point at which data collection stops.
  • Data remains queryable: Log data collected by your existing Sophos SVA log collectors is ingested into the Sophos XDR platform and can be queried just as it is today. You won't lose access to this data.
  • Take the time you need: While we recommend completing the cutover to XDR data collectors promptly, the migration isn't an emergency. Your existing collectors will continue to function until you're ready to transition.

Note

Once you power off an old SVA log collector and bring up the replacement XDR data collector, new log data will be collected by the XDR data collector. Historical data collected by the old SVA log collector before cutover remains available in Sophos XDR.

Frequently asked questions

What happens if I don't migrate?

Sophos log collectors will reach the end of support. At some point in the future, Sophos SVA log collectors will no longer be supported. Migration to Sophos XDR data collectors ensures you continue to receive updates, support, and new features.

New data collector deployments require Sophos XDR. After migration, you won't be able to deploy new Sophos SVA log collectors. Any new log collector instances must be created as Sophos XDR data collectors through the Sophos XDR console.

How soon do I need to migrate?

Your existing Sophos log collectors will continue to operate and send data throughout the migration period. Data collected by your current SVA log collectors is still ingested, stored, and queryable in Sophos XDR. While we recommend completing the cutover promptly, there's no immediate data loss if you need time to plan the transition. See Data continuity during migration for more detail.