Skip to content

Integrate OPNsense

You can integrate OPNsense with Sophos XDR so that it sends data to Sophos for analysis. The integration uses a data collector, which receives third-party data and sends it to the Sophos Data Lake.

Key steps

The key steps in an OPNsense integration are as follows:

  • Install and configure a data collector if you haven't already done so.
  • Configure OPNsense to send data to the data collector.

Requirements

The following is required for OPNsense configuration:

  • Access to the OPNsense console.
  • Check the requirements for the data collector you're using by reviewing the guides at Data collectors.

Add an OPNsense integration

To integrate OPNsense, you must first install a Sophos XDR data collector, then configure OPNsense to send logs to it.

Install and configure a data collector

OPNsense must be configured to send logs to the Sophos XDR data collector. Logs are filtered and correlated in real-time for various security event observations. Go to Data collectors and follow the guide for creating a data collector if you haven't already done so.

Configure logging and enable monitoring

When the data collector is ready, you can configure OPNsense to send us data.

To set up event forwarding via syslog, do as follows:

  1. Follow the steps in OPNsense's own guide: Logging.
  2. Be sure to configure the following parameters:

    • Enabled: Turn on.
    • Transport: Choose UDP(4).
    • Applications: Choose filter (filterlog).
    • Levels: Select info, notice, warn, error, critical, alert, and emergency.
    • Facilities: Leave blank.
    • Hostname: Enter the Sophos XDR data collector's server IP address.
    • Port: Enter 514.
    • rfc5424: Turn off.
    • Description: Enter FilterLog.

    OPNsense configuration. Your OPNsense data should now appear in the Sophos Data Lake after validation.

Configuration notes

Keep the following in mind during OPNsense configuration:

  • You can configure multiple instances of OPNsense to send data to Sophos via the same data collector. After you finish integration, repeat the steps in this section for your other instances of OPNsense.

Additional resources

For more information on configuring OPNsense, see the following documents: