Skip to content

Box

You can integrate Box with Sophos XDR so that it sends data to Sophos for analysis.

This page gives you an overview of the integration.

Box product overview

Box is a cloud content management and collaboration platform that lets organizations store, manage, share, and collaborate on content securely in the cloud, with enterprise-grade security, governance, and compliance controls.

What we ingest

Sophos XDR collects Box events through the Box Events API, using a Box application you authorize (OAuth 2.0 server authentication). The following log categories are collected:

  • Enterprise events: Box enterprise activity events, such as content access, collaboration, sharing, and administrative actions.
  • Login events: User authentication events.
  • Box Shield alerts: Box Shield threat detections, including malicious content, suspicious sessions, suspicious locations, anomalous downloads, and blocked downloads (requires an active Box Shield subscription).

Event and data types

We ingest the following event and data types from Box:

  • Enterprise events: Box enterprise activity events across content access, collaboration, sharing, and administrative actions, including the user, item, and action. Normalized to cloud audit telemetry.
  • Login events: User sign-in activity, including the user, result, and source. Normalized to authentication telemetry.
  • Box Shield alerts: Box Shield threat detections such as suspicious sessions and locations, anomalous downloads, and blocked downloads. Normalized to third-party security alert telemetry, and to antivirus telemetry for malicious-content detections.

Data provided by this integration

Data provided by Box gets normalized to the following schemas:

  • antivirus
  • auth
  • cloudaudit
  • thirdpartyalert

For more information about using schemas in Data Lake Search, see Schemas and logical types.

Vendor documentation