Skip to content

Supported schemas for custom parsers

A Sophos Next-Gen SIEM subscription is required to use custom parsers. See Sophos Next-Gen SIEM overview.

Custom parsers can normalize data to a subset of Sophos XDR event schemas. Use this page to identify the supported schemas and view the fields available for normalization.

The following event schemas can be used as destinations when you normalize data with a custom parser.

The schema documentation above shows the fields available for normalization.

To populate a field in Sophos XDR, the corresponding parser field must exist in the original data.

Normalized data appears in the Normalized Data tab of event details and is searchable only when the corresponding data exists in the original message.

The Schema Library in Data Lake Search shows only searchable fields. For details, see Schema Library.