Integrate pfSense
You can integrate pfSense with Sophos XDR so that it sends data to Sophos for analysis. The integration uses a data collector, which receives third-party data and sends it to the Sophos Data Lake.
Key steps
The key steps in a pfSense integration are as follows:
- Install and configure a data collector if you haven't already done so.
- Configure pfSense to send data to the data collector.
Requirements
The following is required for pfSense configuration:
- Access to the pfSense administration console.
- Check the requirements for the data collector you're using by reviewing the guides at Data collectors.
Add a pfSense integration
To integrate pfSense, you must first install a Sophos XDR data collector, then configure pfSense to send logs to it.
Install and configure a data collector
pfSense must be configured to send logs to the Sophos XDR data collector. Logs are filtered and correlated in real-time for various security event observations. Go to Data collectors and follow the guide for creating a data collector if you haven't already done so.
Configure logging and enable monitoring
When the data collector is ready, you can configure pfSense to send us data.
To set up event forwarding via syslog, do as follows:
- Follow the steps in pfSense's own guide: Log Settings.
- In General Logging Options, choose BSD (RFC 3164, default) as the log message format.
-
In Remote Logging Options, configure the following parameters:
- Enable Remote Logging: Turn on.
- Source Address: Choose the interface or network with access to the Sophos XDR data collector.
- IP Protocol: Choose IPv4.
- Remote log servers: Enter the Sophos XDR data collector's server IP address.
- Remote Syslog Contents: Choose Firewall Events.
Your pfSense data should now appear in the Sophos Data Lake after validation.
Configuration notes
Keep the following in mind during pfSense configuration:
- You can configure multiple instances of pfSense to send data to Sophos via the same data collector. After you finish integration, repeat the steps in this section for your other instances of pfSense.
Additional resources
For more information on configuring pfSense, see the following documents:
