Skip to content

AWS CloudWatch Logs

You can use Amazon CloudWatch Logs with Sophos XDR by forwarding CloudWatch log data to Amazon S3. After logs are delivered to S3, Sophos XDR can ingest and analyze them using a supported S3 integration method.

Common integrations that use CloudWatch Logs as a source include the following:

This page gives you an overview of the integration.

AWS CloudWatch Logs product overview

Amazon CloudWatch Logs is a log aggregation and monitoring service that centralizes logs from AWS services, applications, and systems (for example, EC2, AWS CloudTrail, Route 53) into log groups and streams in a single, highly scalable service.

What we ingest

Sophos XDR supports collecting logs that are forwarded from Amazon CloudWatch Logs through Amazon S3. Log data is delivered using a CloudWatch Logs subscription filter, Amazon Kinesis Data Firehose, and an Amazon S3 bucket that Sophos XDR ingests. CloudWatch Logs acts as a transport for AWS service and application logs.

Sophos XDR normalizes supported log formats according to their corresponding integrations. Logs in unsupported or custom formats are normalized to the generic schema. The following log categories are collected:

  • Supported AWS logs: AWS service logs forwarded from CloudWatch Logs that are in a format Sophos XDR supports (for example, CloudTrail and WAF logs).

Event and data types

We ingest the following event and data types from AWS CloudWatch Logs:

  • Supported AWS logs: The log records you route through CloudWatch Logs. Log types Sophos XDR supports are normalized according to their specific integration (for example, CloudTrail to cloud audit, WAF to HTTP telemetry). Logs in any other or custom format are not supported and are normalized to the generic schema.

Data provided by this integration

AWS CloudWatch Logs is a transport, so it doesn't produce a dedicated telemetry type in Sophos XDR. Instead, it serves as a transport for other AWS integrations.

Supported log types are normalized according to their corresponding integrations. For example, see the following guides:

Logs in unsupported formats are normalized to the generic schema.

For more information about using schemas in Data Lake Search, see Schemas and logical types.

Vendor documentation