Wazuh fix note · Sophos Firewall syslog

Sophos Firewall logs not showing in Wazuh

Sophos Firewall can send syslog in two layouts. Wazuh 4.14.7's stock decoder reads only the legacy one, which starts device="SFW" date=... time=.... The Central Reporting layout, which starts device_name="SFW" timestamp="...", matches no decoder: the line falls through to a generic level 2 rule and never becomes an alert. We measured both, and tested two fixes.

Dong Nguyen, ATK New Technology · 2 October 2026 · measured on Wazuh 4.14.7 (manager container, syslog over UDP 514)

Stuck on this right now? Email your custom rules or decoders, one sample log line and your Wazuh version to dongnx@atkvn.com. We run them on that exact version and reply within 24 hours with what we find. Free. Remove hostnames, IPs and usernames first. Rather not send them? Run the free pre-check in your browser; your files never leave your machine. Rather have it fixed? USD 149 fixed price per problem, reproduced on your version, and you pay only after it works on your system. Our first three customers pay USD 49 for one fix, in exchange for an anonymised write-up we can publish.


How to check in one minute

1. Which layout is arriving? With <logall>yes</logall> on for a few minutes:

grep -e '^.*device="' -e 'device_name="' /var/ossec/logs/archives/archives.log | tail -n 3
  • Lines starting device="SFW" date=2026-10-02 time=15:00:01 ...: legacy layout. The stock decoder reads it; if you still see nothing, the issue is elsewhere.
  • Lines starting device_name="SFW" timestamp="2026-10-02T15:00:01+0700" ...: Central Reporting layout. This page.

2. Confirm in logtest. Paste one line into /var/ossec/bin/wazuh-logtest. Legacy: name: 'sophos-fw'. Central Reporting: No decoder matched. Turn logall off afterwards.

Why it happens

The stock decoder in ruleset/decoders/0510-sophos_fw_decoders.xml on 4.14.7 is anchored on the legacy start of line:

<prematch>^device="\w*"\s+date=\d+-\d+-\d+\s+time=</prematch>

Sophos's syslog guide documents both layouts: the legacy one (device, date, time, timezone, device_id, status) and the Central Reporting one (device_name, ISO timestamp, device_model, device_serial_id, log_subtype, no status). The stock rules (0705-sophos_fw_rules.xml, 70020–) key on the decoded status, so a Central Reporting line has neither the decoder nor the field the rules need.

Denied-traffic line sent (UDP 514, Wazuh 4.14.7)Result
legacy: device="SFW" date=... log_subtype="Denied" status="Deny" ...sophos-fw → 70021, level 5, Traffic Denied
Central Reporting: device_name="SFW" timestamp="..." log_subtype="Denied" ...No decoder matched → generic 1002, level 2 → no alert

Fix

Option 1: send the legacy layout

Sophos's syslog guide calls the legacy layout Device standard and the new one Central reporting. If your firewall's syslog server settings let you pick the format, pick the device-standard one and the stock decoder and rules apply as they are. Other tools reading the same stream may expect the new layout; check before switching.

Option 2: decode the Central Reporting layout

Save as /var/ossec/etc/decoders/sophos_crf_decoders.xml:

<!-- Sophos Firewall, Central Reporting syslog format (device_name="..." timestamp="..."). ATK, tested on Wazuh 4.14.7. -->
<decoder name="sophos-fw-crf">
  <prematch>^device_name="\S+" timestamp="</prematch>
</decoder>

<decoder name="sophos-fw-crf-fields">
  <parent>sophos-fw-crf</parent>
  <regex type="pcre2">log_type="([^"]*)" log_component="([^"]*)" log_subtype="([^"]*)"</regex>
  <order>log_type, log_component, log_subtype</order>
</decoder>

<decoder name="sophos-fw-crf-fields">
  <parent>sophos-fw-crf</parent>
  <regex type="pcre2">\bfw_rule_id="([^"]*)"</regex>
  <order>fw_rule_id</order>
</decoder>

<decoder name="sophos-fw-crf-fields">
  <parent>sophos-fw-crf</parent>
  <regex type="pcre2">\bsrc_ip="([^"]*)"</regex>
  <order>srcip</order>
</decoder>

<decoder name="sophos-fw-crf-fields">
  <parent>sophos-fw-crf</parent>
  <regex type="pcre2">\bdst_ip="([^"]*)"</regex>
  <order>dstip</order>
</decoder>

<decoder name="sophos-fw-crf-fields">
  <parent>sophos-fw-crf</parent>
  <regex type="pcre2">\bprotocol="([^"]*)"</regex>
  <order>protocol</order>
</decoder>

<decoder name="sophos-fw-crf-fields">
  <parent>sophos-fw-crf</parent>
  <regex type="pcre2">\bsrc_port="([^"]*)"</regex>
  <order>srcport</order>
</decoder>

<decoder name="sophos-fw-crf-fields">
  <parent>sophos-fw-crf</parent>
  <regex type="pcre2">\bdst_port="([^"]*)"</regex>
  <order>dstport</order>
</decoder>

Save as /var/ossec/etc/rules/sophos_crf_rules.xml (IDs in the custom range; change them if they collide):

<group name="sophos,firewall,">
  <rule id="100320" level="0">
    <decoded_as>sophos-fw-crf</decoded_as>
    <description>Sophos Firewall (Central Reporting format) event.</description>
  </rule>

  <rule id="100321" level="5">
    <if_sid>100320</if_sid>
    <field name="log_type">^Firewall$</field>
    <field name="log_subtype">^Denied$</field>
    <description>Sophos Firewall: traffic denied from $(srcip) to $(dstip):$(dstport).</description>
    <group>firewall_block,</group>
  </rule>

  <rule id="100322" level="3">
    <if_sid>100320</if_sid>
    <field name="log_type">^Firewall$</field>
    <field name="log_subtype">^Allowed$</field>
    <description>Sophos Firewall: traffic allowed from $(srcip) to $(dstip):$(dstport).</description>
  </rule>

  <rule id="100323" level="10" frequency="18" timeframe="45" ignore="240">
    <if_matched_sid>100321</if_matched_sid>
    <same_source_ip />
    <description>Sophos Firewall: multiple denied connections from $(srcip).</description>
    <group>firewall_block,</group>
  </rule>
</group>

Then /var/ossec/bin/wazuh-analysisd -t and restart. The source address is written as srcip (not src_ip as in the stock decoder), so <same_source_ip> correlation and the firewall-drop active response can use it.

What we measured with Option 2

SentBeforeAfter
1 Central Reporting denied line0 alerts100321, level 5, srcip/dstip/dstport read
the same, 18 times in a few seconds—17 × 100321, then 100323 level 10
Sophos's own Central Reporting example (Allowed)no decoder100322, level 3
1 legacy denied line7002170021 (untouched)

wazuh-analysisd -t: no warnings, no 7617/7619.

Limits of what we measured

Measured on a Wazuh 4.14.7 manager container receiving syslog over UDP 514 from 127.0.0.1, and in wazuh-logtest. We did not run a Sophos Firewall. The Allowed line is Sophos's published example; the Denied lines were written by us in the same layout, with the fields a firewall-rule log carries. The decoder covers firewall-rule events only, not admin login, IPS, web filter or VPN events. We have not checked which SFOS release made Central Reporting the default, or the exact menu name for the format setting.

Have it working

Need more Sophos event types, or another log source, decoded and alerting the way you want? Send 5–10 sample lines (masked) and your Wazuh version to dongnx@atkvn.com. We write the decoder and rules, test them on your exact version, and send the files with apply and rollback steps. USD 149 per log source, paid after it works on your system.