Aryaka
You can integrate Aryaka with Sophos XDR so that it sends data to Sophos for analysis.
This page gives you an overview of the integration.
Aryaka product overview
Aryaka provides Unified SASE as a Service, which includes wide-area software-defined networking connectivity, application delivery, and network security.
What we ingest
Sophos XDR collects Aryaka data via syslog by listening for messages your Aryaka deployment forwards to a Sophos XDR data collector. Records are parsed from JSON. The following data is collected:
- Security alerts: Aryaka network security events, including intrusion detection signature matches and network activity flagged by domain and URL reputation, each carrying the signature or finding, severity, action, and source and destination endpoints.
Event and data types
All Aryaka events are normalized uniformly to third-party security alert telemetry. They include:
- Intrusion detections: IDPS signature matches, such as Emerging Threats rules, with classification, severity, and action taken.
- Network activity and reputation: Connection activity flagged by domain and URL reputation scoring, including the host, category, and reputation score.
Data provided by this integration
Data provided by Aryaka gets normalized to the following schemas:
thirdpartyalert
For more information about using schemas in Data Lake Search, see Schemas and logical types.