Skip to content

OPNsense

You can integrate OPNsense with Sophos XDR so that it sends data to Sophos for analysis.

This page gives you an overview of the integration.

OPNsense product overview

OPNsense is an open-source, FreeBSD-based firewall and routing platform founded by Deciso B.V. as a fork of pfSense, offering firewalling, traffic shaping, intrusion detection, VPN, and related network security services managed through a web interface.

What we ingest

Sophos XDR collects OPNsense syslog data by listening for firewall filter-log (filterlog) messages your OPNsense deployment forwards to a Sophos XDR data collector. The following log categories are collected:

  • Firewall traffic 1: Firewall pass and block events for TCP, UDP, and ICMP traffic.

Event and data types

We ingest the following event and data types from OPNsense:

  • Firewall traffic 1: Firewall filter log pass and block events for TCP, UDP, and ICMP traffic, including source and destination addresses, ports, and the action. Normalized to netflow telemetry.

Data provided by this integration

Data provided by OPNsense gets normalized to the following schemas:

  • netflow 1

For more information about using schemas in Data Lake Search, see Schemas and logical types.

Vendor documentation


  1. Netflow telemetry is only available to NG-SIEM subscribers.