Skip to content

Integrate Aryaka

You can integrate Aryaka with Sophos XDR so that it sends data to Sophos for analysis. The integration uses a data collector, which receives third-party data and sends it to the Sophos Data Lake.

Key steps

The key steps in an Aryaka integration are as follows:

  • Install and configure a data collector if you haven't already done so.
  • Configure Aryaka to send data to the data collector.

Requirements

The following is required for Aryaka configuration:

  • Access to MyAryaka.
  • Check the requirements for the data collector you are using by reviewing the guides at Data collectors.

Add an Aryaka integration

To integrate Aryaka, you must first install a Sophos XDR data collector, then configure Aryaka to send logs to it.

Install and configure a data collector

Aryaka must be configured to send logs to the Sophos XDR data collector. Logs are filtered and correlated in real-time for various security event observations. Go to Data collectors and follow the guide for creating a data collector if you haven't already done so.

Configure logging and enable monitoring

Once the data collector is ready, you can configure Aryaka to send us data.

To set up event forwarding via syslog, do as follows:

  1. Follow the steps in Aryaka's own guide: Configure SIEM integration.
  2. Be sure the configured IP address matches the Sophos XDR data collector's server IP address.

Your Aryaka data should now appear in the Sophos Data Lake after validation.

Additional resources

For more information on configuring Aryaka, see the following documents: