S3 Ingest - Sophos-Managed (without token)
A Sophos Next-Gen SIEM subscription is required to integrate using custom transport methods. See Sophos Next-Gen SIEM overview.
You can integrate custom integrations with Sophos XDR using a Sophos-managed AWS S3 bucket so that it sends data to Sophos for analysis.
This page gives you an overview of the integration.
Sophos-managed (without token) product overview
Sophos-managed S3 (without ownership token) lets Sophos XDR ingest logs through an Amazon S3 bucket that Sophos manages, removing the need to run your own S3 infrastructure. This variant is used when the data source vendor does not require an ownership-challenge token to be written to the S3 destination.
What we ingest
Sophos XDR provides a managed S3 destination. You configure your data source to export logs to it. This is a transport for whatever logs the data source exports. Sophos XDR normalizes only log formats it already supports. Logs in a different or custom format are not supported and are normalized to the generic schema. The following log categories are collected:
- Delivered logs: Logs a data source exports to the Sophos-managed S3 destination.
Event and data types
We ingest the following event and data types from Sophos-managed S3 (without token):
- Delivered logs: The log records exported to the managed S3 destination. Log types Sophos XDR supports are normalized according to their specific integration; logs in any other or custom format are not supported and are normalized to the generic schema.
Data provided by this integration
This is a transport, so the schemas depend on the underlying log types you deliver. Supported types normalize per their own integrations; logs in an unsupported format are normalized to the generic schema.
For more information about using schemas in Data Lake Search, see Schemas and logical types.