Supported schemas for custom parsers
A Sophos Next-Gen SIEM subscription is required to use custom parsers. See Sophos Next-Gen SIEM overview.
Custom parsers can normalize data to a subset of Sophos XDR event schemas. Use this page to identify the supported schemas and view the fields available for normalization.
The following event schemas can be used as destinations when you normalize data with a custom parser.
- Antivirus schema
- API Call schema
- Authentication schema
- Cloud Audit schema
- DHCP schema
- DNS schema
- Email schema
- Encrypt schema
- File Modification schema
- Generic schema
- HTTP schema
- Management Event schema
- Netflow schema
- NIDS schema
- Process schema
- Registry schema
- Third Party Alerts schema
The schema documentation above shows the fields available for normalization.
To populate a field in Sophos XDR, the corresponding parser field must exist in the original data.
Normalized data appears in the Normalized Data tab of event details and is searchable only when the corresponding data exists in the original message.
The Schema Library in Data Lake Search shows only searchable fields. For details, see Schema Library.