How to check in one minute
1. Which layout is arriving? With <logall>yes</logall> on for a few minutes:
grep -e '^.*device="' -e 'device_name="' /var/ossec/logs/archives/archives.log | tail -n 3
- Lines starting
device="SFW" date=2026-10-02 time=15:00:01 ...: legacy layout. The stock decoder reads it; if you still see nothing, the issue is elsewhere. - Lines starting
device_name="SFW" timestamp="2026-10-02T15:00:01+0700" ...: Central Reporting layout. This page.
2. Confirm in logtest. Paste one line into /var/ossec/bin/wazuh-logtest. Legacy: name: 'sophos-fw'. Central Reporting: No decoder matched. Turn logall off afterwards.
Why it happens
The stock decoder in ruleset/decoders/0510-sophos_fw_decoders.xml on 4.14.7 is anchored on the legacy start of line:
<prematch>^device="\w*"\s+date=\d+-\d+-\d+\s+time=</prematch>
Sophos's syslog guide documents both layouts: the legacy one (device, date, time, timezone, device_id, status) and the Central Reporting one (device_name, ISO timestamp, device_model, device_serial_id, log_subtype, no status). The stock rules (0705-sophos_fw_rules.xml, 70020–) key on the decoded status, so a Central Reporting line has neither the decoder nor the field the rules need.
| Denied-traffic line sent (UDP 514, Wazuh 4.14.7) | Result |
|---|---|
legacy: device="SFW" date=... log_subtype="Denied" status="Deny" ... | sophos-fw → 70021, level 5, Traffic Denied |
Central Reporting: device_name="SFW" timestamp="..." log_subtype="Denied" ... | No decoder matched → generic 1002, level 2 → no alert |
Fix
Option 1: send the legacy layout
Sophos's syslog guide calls the legacy layout Device standard and the new one Central reporting. If your firewall's syslog server settings let you pick the format, pick the device-standard one and the stock decoder and rules apply as they are. Other tools reading the same stream may expect the new layout; check before switching.
Option 2: decode the Central Reporting layout
Save as /var/ossec/etc/decoders/sophos_crf_decoders.xml:
<!-- Sophos Firewall, Central Reporting syslog format (device_name="..." timestamp="..."). ATK, tested on Wazuh 4.14.7. -->
<decoder name="sophos-fw-crf">
<prematch>^device_name="\S+" timestamp="</prematch>
</decoder>
<decoder name="sophos-fw-crf-fields">
<parent>sophos-fw-crf</parent>
<regex type="pcre2">log_type="([^"]*)" log_component="([^"]*)" log_subtype="([^"]*)"</regex>
<order>log_type, log_component, log_subtype</order>
</decoder>
<decoder name="sophos-fw-crf-fields">
<parent>sophos-fw-crf</parent>
<regex type="pcre2">\bfw_rule_id="([^"]*)"</regex>
<order>fw_rule_id</order>
</decoder>
<decoder name="sophos-fw-crf-fields">
<parent>sophos-fw-crf</parent>
<regex type="pcre2">\bsrc_ip="([^"]*)"</regex>
<order>srcip</order>
</decoder>
<decoder name="sophos-fw-crf-fields">
<parent>sophos-fw-crf</parent>
<regex type="pcre2">\bdst_ip="([^"]*)"</regex>
<order>dstip</order>
</decoder>
<decoder name="sophos-fw-crf-fields">
<parent>sophos-fw-crf</parent>
<regex type="pcre2">\bprotocol="([^"]*)"</regex>
<order>protocol</order>
</decoder>
<decoder name="sophos-fw-crf-fields">
<parent>sophos-fw-crf</parent>
<regex type="pcre2">\bsrc_port="([^"]*)"</regex>
<order>srcport</order>
</decoder>
<decoder name="sophos-fw-crf-fields">
<parent>sophos-fw-crf</parent>
<regex type="pcre2">\bdst_port="([^"]*)"</regex>
<order>dstport</order>
</decoder>
Save as /var/ossec/etc/rules/sophos_crf_rules.xml (IDs in the custom range; change them if they collide):
<group name="sophos,firewall,">
<rule id="100320" level="0">
<decoded_as>sophos-fw-crf</decoded_as>
<description>Sophos Firewall (Central Reporting format) event.</description>
</rule>
<rule id="100321" level="5">
<if_sid>100320</if_sid>
<field name="log_type">^Firewall$</field>
<field name="log_subtype">^Denied$</field>
<description>Sophos Firewall: traffic denied from $(srcip) to $(dstip):$(dstport).</description>
<group>firewall_block,</group>
</rule>
<rule id="100322" level="3">
<if_sid>100320</if_sid>
<field name="log_type">^Firewall$</field>
<field name="log_subtype">^Allowed$</field>
<description>Sophos Firewall: traffic allowed from $(srcip) to $(dstip):$(dstport).</description>
</rule>
<rule id="100323" level="10" frequency="18" timeframe="45" ignore="240">
<if_matched_sid>100321</if_matched_sid>
<same_source_ip />
<description>Sophos Firewall: multiple denied connections from $(srcip).</description>
<group>firewall_block,</group>
</rule>
</group>
Then /var/ossec/bin/wazuh-analysisd -t and restart. The source address is written as srcip (not src_ip as in the stock decoder), so <same_source_ip> correlation and the firewall-drop active response can use it.
What we measured with Option 2
| Sent | Before | After |
|---|---|---|
| 1 Central Reporting denied line | 0 alerts | 100321, level 5, srcip/dstip/dstport read |
| the same, 18 times in a few seconds | — | 17 × 100321, then 100323 level 10 |
| Sophos's own Central Reporting example (Allowed) | no decoder | 100322, level 3 |
| 1 legacy denied line | 70021 | 70021 (untouched) |
wazuh-analysisd -t: no warnings, no 7617/7619.
Limits of what we measured
Measured on a Wazuh 4.14.7 manager container receiving syslog over UDP 514 from 127.0.0.1, and in wazuh-logtest. We did not run a Sophos Firewall. The Allowed line is Sophos's published example; the Denied lines were written by us in the same layout, with the fields a firewall-rule log carries. The decoder covers firewall-rule events only, not admin login, IPS, web filter or VPN events. We have not checked which SFOS release made Central Reporting the default, or the exact menu name for the format setting.