Skip to content

HTTP Ingest

A Sophos Next-Gen SIEM subscription is required to integrate using custom transport methods. See Sophos Next-Gen SIEM overview.

You can integrate custom integrations with Sophos XDR using an HTTP Ingest custom transport so that it sends data to Sophos for analysis.

This page gives you an overview of the integration.

HTTP Ingest product overview

HTTP Ingest is a Sophos XDR transport method that exposes an HTTPS endpoint to which any data source can POST security logs in a streaming fashion, enabling near-real-time ingestion. It provides a general-purpose way to send logs to Sophos XDR from any source capable of making HTTP POST requests using the required API conventions.

What we ingest

Once provisioned, Sophos XDR exposes an HTTPS endpoint that accepts POST requests from your data source. HTTP Ingest is a transport for whatever logs you send to it. Sophos XDR normalizes only log formats it already supports; logs sent in a different or custom format are not supported and are normalized to the generic schema. The following log categories are collected:

  • Posted logs: Security logs a data source sends to the HTTP Ingest endpoint.

Event and data types

We ingest the following event and data types via HTTP Ingest:

  • Posted logs: The log records posted to the endpoint. Log types Sophos XDR supports are normalized according to their specific integration; logs in any other or custom format are not supported and are normalized to the generic schema.

Data provided by this integration

HTTP Ingest is a transport, so the schemas depend on the underlying log types you send. Supported types normalize per their own integrations. Logs in an unsupported format are normalized to the generic schema.

For more information about using schemas in Data Lake Search, see Schemas and logical types.