Infoblox DNS
You can integrate Infoblox DNS with Sophos XDR so that it sends data to Sophos for analysis.
This page gives you an overview of the integration.
Infoblox DNS product overview
Infoblox provides core network services (DNS, DHCP, and IP address management (DDI)) together with DNS-layer security, using DNS as a control point to detect and block malicious and high-risk domains across on-premises, cloud, and hybrid environments.
What we ingest
Sophos XDR collects Infoblox DNS data via CEF over syslog by listening for Infoblox Data Connector messages that your deployment forwards to a Sophos XDR data collector. The following log categories are collected:
- DNS activity: DNS query and response events that the Infoblox Data Connector forwards.
Event and data types
We ingest the following event and data types from Infoblox DNS:
- DNS activity: DNS query and response events, including the queried domain, record type, client, and response. Normalized to DNS query telemetry.
Data provided by this integration
Data provided by Infoblox DNS gets normalized to the following schemas:
dnsquery
For more information about using schemas in Data Lake Search, see Schemas and logical types.