Microsoft Azure Event Hubs
A Sophos Next-Gen SIEM subscription is required to integrate using custom transport methods. See Sophos Next-Gen SIEM overview.
You can integrate custom integrations with Sophos XDR using Microsoft Azure Event Hubs so that it sends data to Sophos for analysis.
This page gives you an overview of the integration.
Azure Event Hubs product overview
Azure Event Hubs is Microsoft Azure's fully managed, real-time event streaming and data ingestion service, capable of ingesting millions of events per second with multi-protocol support (Apache Kafka, AMQP, and HTTPS). As a Sophos XDR transport, Azure services stream their diagnostic logs to an event hub that Sophos XDR consumes.
What we ingest
Sophos XDR collects logs from an Azure Event Hub: you enable Azure Monitor diagnostic settings on your Azure services and stream the selected log categories to an event hub that Sophos XDR ingests. This is a transport for whichever Azure logs you stream to it. Sophos XDR normalizes only log formats it already supports. Logs in a different or custom format are not supported and are normalized to the generic schema. The following log categories are collected:
- Streamed Azure logs: Azure diagnostic logs streamed to the event hub, such as Azure Firewall, Application Gateway, and Front Door.
Event and data types
We ingest the following event and data types from Azure Event Hubs:
- Streamed Azure logs: The log records streamed to the event hub. Log types Sophos XDR supports are normalized according to their specific integration. Logs in any other or custom format are not supported and are normalized to the generic schema.
Data provided by this integration
This is a transport, so the schemas depend on the underlying Azure log types you stream. Supported types normalize per their own integrations. Logs in an unsupported format are normalized to the generic schema.
For more information about using schemas in Data Lake Search, see Schemas and logical types.