Skip to content

Integrate Darktrace DETECT

You can integrate Darktrace DETECT with Sophos XDR so that it sends data to Sophos for analysis. The integration uses a data collector, which receives third-party data and sends it to the Sophos Data Lake.

Key steps

The key steps in a Darktrace DETECT integration are as follows:

  • Install and configure a data collector if you haven't already done so.
  • Configure Darktrace to send data to the data collector.

Requirements

The following is required for Darktrace DETECT configuration:

  • An administrator account in the Darktrace Portal.
  • Check the requirements for the data collector you are using by reviewing the guides at Data collectors.

Add a Darktrace DETECT integration

To integrate Darktrace DETECT, you must first install a Sophos XDR data collector, then configure Darktrace to send logs to it.

Install and configure a data collector

Darktrace DETECT must be configured to send logs to the Sophos XDR data collector. Logs are filtered and correlated in real-time for various security event observations. Go to Data collectors and follow the guide for creating a data collector if you haven't already done so.

Configure logging and enable monitoring

Once the data collector is ready, you can configure Darktrace DETECT to send us data.

You can configure the logs using either CEF or JSON. Click the tab below for each set of instructions.

To set up event forwarding via syslog using CEF, do as follows:

  1. Sign in to Darktrace DETECT.
  2. In the Threat Visualizer, go to Admin > System Config.
  3. Click Modules and choose Syslog from the available Workflow Integrations.
  4. On the Syslog page, select Syslog CEF.
  5. Click New.

    The Syslog configuration settings are shown. We recommend that you do all the configuration before you turn on Send Alerts.

  6. In Server, enter the Sophos XDR data collector's server IP address.

  7. In Server Port, enter 514.
  8. Turn on Show Advanced Options.
  9. In the first section, turn on Send Alerts Using TCP.
  10. Turn on Send AI Analyst Alerts.
  11. Set Minimum AI Analyst Incident Event Score and Minimum AI Analyst Incident Score to 0. This maximizes the alerts sent to Sophos XDR.
  12. Click Add.
  13. Go back to the top of the page and click Verify alert sending. This sends a test alert to your XDR data collector.
  14. Turn on Send Alerts and save your changes.

To set up event forwarding via syslog using JSON, do as follows:

  1. Sign in to Darktrace DETECT.
  2. In the Threat Visualizer, go to Admin > System Config.
  3. Click Modules and choose Syslog from the available Workflow Integrations.
  4. On the Syslog page, select Syslog JSON.
  5. Click New.

    The Syslog configuration settings are shown. We recommend that you do all the configuration before you turn on Send Alerts.

  6. Turn on JSON Syslog Alerts.

  7. In JSON Syslog Server, enter the Sophos XDR data collector's server IP address.
  8. Turn on JSON Syslog TCP Alerts.
  9. Turn on Send Alerts and save your changes.

Your Darktrace DETECT data should now appear in the Sophos Data Lake after validation.

Configuration notes

Keep the following in mind during Darktrace DETECT configuration:

  • You can configure multiple instances of Darktrace to send data to Sophos via the same data collector. After you finish integration, repeat the steps in this section for your other instances of Darktrace.

Additional resources

For more information on configuring Darktrace DETECT, see the following documents: