Overview

Sophos Central is a cloud based device which is added to the UI using API call. This document will help you with the steps to ingest the Sophos Central with Seceon SIEM to have a better visibility of threats happening in your environment.

Steps Of Integration

To add the Sophos Central support Follow the steps that are mentioned below.

Steps to Generate API Token (Sophos Central Console):

Steps to Configure Sophos Central (Seceon UI):

Note: Actual URL you will get it from Sophos central console, while generating the API token.

{"api": "https://api5.central.sophos.com/gateway"}

Verification:

For seeing the sophos central logs please try to generate below mentioned events to see the logs on UI:

Sophos Central doc - https://support.sophos.com/support/s/article/KB-000038309?language=en_US ,

To see the logs on UI navigate to System Tab >> Log/Flow Collection tab .