Skip to content

S3 Ingest - Sophos-Managed (with token)

A Sophos Next-Gen SIEM subscription is required to integrate using custom transport methods. See Sophos Next-Gen SIEM overview.

You can integrate custom integrations with Sophos XDR using a Sophos-managed AWS S3 bucket so that it sends data to Sophos for analysis.

This page gives you an overview of the integration.

Sophos-managed (with token) product overview

Sophos-managed S3 (with ownership token) lets Sophos XDR ingest logs through an Amazon S3 bucket that Sophos manages, removing the need to run your own S3 infrastructure. This variant is used when the data source vendor requires an ownership-challenge token to be written to the S3 destination to verify it before exporting logs.

What we ingest

Sophos XDR provides a managed S3 destination. You configure your data source to export logs to it and supply the ownership-challenge token so the vendor can verify the destination. This is a transport for whatever logs the data source exports. Sophos XDR normalizes only log formats it already supports; logs in a different or custom format are not supported and are normalized to the generic schema. The following log categories are collected:

  • Delivered logs: Logs a data source exports to the Sophos-managed S3 destination.

Event and data types

We ingest the following event and data types from Sophos-managed S3 (with token):

  • Delivered logs: The log records exported to the managed S3 destination. Log types Sophos XDR supports are normalized according to their specific integration. Logs in any other or custom format are not supported and are normalized to the generic schema.

Data provided by this integration

This is a transport, so the schemas depend on the underlying log types you deliver. Supported types normalize per their own integrations. Logs in an unsupported format are normalized to the generic schema.

For more information about using schemas in Data Lake Search, see Schemas and logical types.

Vendor documentation