AWS VPC Flow Logs
You can integrate AWS VPC Flow Logs with Sophos XDR so that it sends data to Sophos for analysis.
This page gives you an overview of the integration.
AWS VPC Flow Logs product overview
AWS VPC Flow Logs is an Amazon VPC feature that captures information about the IP traffic going to and from network interfaces in your VPC, recording each flow's source and destination IP address and port, protocol, packet and byte counts, and whether the traffic was accepted or rejected.
What we ingest
Sophos XDR collects AWS VPC Flow Logs from an Amazon S3 bucket: you deploy a CloudFormation template that provisions a Lambda function, which forwards flow log files to Sophos XDR as they are delivered to the bucket. Logs must use the default VPC Flow Logs format. The following log categories are collected:
- Network flows 1: VPC network-interface IP traffic flow records.
Event and data types
We ingest the following event and data types from AWS VPC Flow Logs:
- Network flows 1: VPC network-interface IP traffic flow records (5-tuple), including source and destination IP and port, protocol, packet and byte counts, and the accept or reject action. Normalized to netflow telemetry.
Data provided by this integration
Data provided by AWS VPC Flow Logs gets normalized to the following schemas:
netflow1
For more information about using schemas in Data Lake Search, see Schemas and logical types.