Skip to content

SonicWall SonicOS

You can integrate SonicWall SonicOS with Sophos XDR so that it sends alerts to Sophos for analysis.

This page gives you an overview of the integration.

SonicWall SonicOS product overview

SonicWall delivers an automated, real-time platform for breach detection and prevention. It offers a multi-engine sandbox approach that stops threats at the gateway, ensuring business continuity and enhancing network efficiency.

What we ingest

Sophos XDR collects SonicWall firewall data over syslog forwarded from your SonicOS device (or syslog forwarder) to a Sophos XDR data collector. The same logical event types can arrive in more than one body format, and classification is based on message content rather than transport. Device identity is taken from the sn= serial in the native format, or from the syslog hostname immediately before the CEF payload in CEF syslog. We accept the following SonicWall log formats:

  • Native SonicWall syslog: After any syslog header, the body begins with id=, sn=, and time="...", followed by additional key=value pairs such as msg, src, dst, proto, fw_action, and appName.
  • CEF over syslog: The payload contains CEF:0|SonicWall|... or CEF:0|SONICWALL|... (CEF 0.x), optionally after a syslog timestamp and host. Extensions follow standard CEF key=value conventions.

SonicOS sends these messages exactly as configured in your logging profile. Which event types and fields appear depends on your firmware version, log category settings, and feature licensing. The same activity may appear as native or CEF depending on device settings. For example, DHCP-related normalization can cover more event types in CEF syslog than in native syslog.

Event and data types

We ingest the following event and data types from SonicWall:

  • Session and forwarding telemetry: Connection open and close, drops, and policy-related session summaries: netflow-style telemetry.
  • IPS / gateway security / anti-threat: IPS and gateway threat events: network IDS-style telemetry, including rules and signatures, severity, endpoints, and MAC addresses when logged.
  • Web / HTTP / content policy: HTTP proxy, CFS, and related web activity: HTTP-style telemetry.
  • DNS: DNS query logging: DNS telemetry. Some DNS security events also surface network IDS-style fields.
  • DHCP: DHCP client and lease events: DHCP telemetry when those message types are present.
  • Authentication: Administrative and SSL VPN login, logoff, and password-related messages when logged in the expected form: authentication telemetry.
  • Management and configuration: Audited administrative changes: management-event telemetry.
  • Other SonicWall syslog: Remaining matching traffic ingested and searchable, often with lighter normalization.

Data provided by this integration

Data provided by SonicWall SonicOS gets normalized to the following schemas:

  • dhcp
  • auth
  • dns
  • http
  • netflow
  • nids

For more information about using schemas in Data Lake Search, see Schemas and logical types.

Vendor documentation