Skip to content

S3 Ingest - Customer-managed

A Sophos Next-Gen SIEM subscription is required to integrate using custom transport methods. See Sophos Next-Gen SIEM overview.

You can integrate custom integrations with Sophos XDR using a customer-managed AWS S3 bucket so that it sends data to Sophos for analysis.

This page gives you an overview of the integration.

Customer-managed S3 product overview

Customer-managed S3 lets Sophos XDR ingest logs that a data source delivers to an Amazon S3 bucket in your own AWS account. It is a general-purpose transport for any data source that can export logs to S3.

What we ingest

Sophos XDR collects logs from an Amazon S3 bucket in your AWS account: your data source writes logs to the bucket, and a forwarding function you deploy sends them to Sophos XDR. This is a transport for whatever logs you route through the bucket. Sophos XDR normalizes only log formats it already supports; logs in a different or custom format are not supported and are normalized to the generic schema. The following log categories are collected:

  • Delivered logs: Logs a data source writes to your S3 bucket.

Event and data types

We ingest the following event and data types from a customer-managed S3:

  • Delivered logs: The log records delivered to your S3 bucket. Log types Sophos XDR supports are normalized according to their specific integration. Logs in any other or custom format are not supported and are normalized to the generic schema.

Data provided by this integration

This is a transport, so the schemas depend on the underlying log types you deliver. Supported types normalize per their own integrations. Logs in an unsupported format are normalized to the generic schema.

For more information about using schemas in Data Lake Search, see Schemas and logical types.

Vendor documentation