Skip to content

WatchGuard Firebox

You can integrate WatchGuard Firebox with Sophos Fusion so that it sends data to Sophos for analysis.

This page gives you an overview of the integration.

WatchGuard Firebox product overview

WatchGuard provides a range of easy-to-deploy and manage firewalls tailored for businesses of every size. Their solutions focus on advanced threat detection and response, empowered by rapid visibility into network activity and backed by threat intelligence.

What we ingest

We ingest WatchGuard Firebox logs in LEEF 1.0 form (LEEF:1.0|WatchGuard|XTM|…). Events are retained and searchable in the Sophos XDR Data Lake.

The integration reads the LEEF header for appliance identity, Fireware version, and event type, then applies specialized normalization to matching events. Other LEEF lines remain ingested and searchable as Firebox telemetry without the extra structure below.

Event and data types

We ingest the following event and data types from WatchGuard Firebox:

  • Authentication and VPN: SSL VPN and IKEv2 sign-in and sign-out, rejected or limited sessions, Mobile VPN with SSL, account lock/unlock after failed attempts, Web UI authentication failures, generic authentication errors, and VPN sessions that fail post-login checks (for example, network access enforcement). Normalized to authentication telemetry.
  • Administrative and configuration audit: Management-driven changes such as security or access configuration (for example, user or group authorization) and license or feature-key administration, with actor and source details when logged. Normalized to cloud audit–style telemetry.
  • APT and file reputation: Advanced threat notifications: threats detected and safe outcomes from submission or inspection, including policy, hashes, endpoints, host or path, proxy type, and email sender or recipients when present. Normalized to antivirus-style telemetry.
  • HTTP and HTTPS proxy traffic: Proxy traffic where the log includes proxy action and a clear request target (hostname or destination name): methods, URL components where available, volume, allow/deny, user on the session when present, and some denies from request format or in-proxy inspection. Normalized to HTTP-style telemetry.
  • Network flows and firewall session records: Allowed and denied connections, policy blocks and autoblock, temporary host blocks (for example port-scan behavior), and non-HTTP proxy traffic logged as flows, with endpoints, ports, protocol, geography when present, and byte or packet counters. Normalized to netflow-style telemetry.
  • Intrusion prevention (IPS): Traffic matching an IPS signature: rule name, category, rule identifier, severity, and CVE reference when present in the rule text. Emitted as third-party security alert telemetry and netflow-style session context.

Data provided by this integration

Data provided by WatchGuard Firebox gets normalized to the following schemas:

  • auth
  • dns
  • http
  • netflow

For more information about using schemas in Data Lake Search, see Schemas and logical types.

Vendor documentation