Skip to content

Integrate Infoblox DNS

You can integrate Infoblox DNS with Sophos XDR so that it sends data to Sophos for analysis. The integration uses a data collector, which receives third-party data and sends it to the Sophos Data Lake.

Key steps

The key steps in an Infoblox DNS integration are as follows:

  • Install and configure a data collector if you haven't already done so.
  • Configure Infoblox DNS to send data to the data collector.

Requirements

The following is required for Infoblox DNS configuration:

  • Check the requirements for the data collector you're using by reviewing the guides at Data collectors.

Add an Infoblox DNS integration

To integrate Infoblox DNS, you must first install a Sophos XDR data collector, then configure Infoblox to send logs to it.

Install and configure a data collector

Infoblox DNS must be configured to send logs to the Sophos XDR data collector. Logs are filtered and correlated in real-time for various security event observations. Go to Data collectors and follow the guide for creating a data collector if you haven't already done so.

Configure logging and enable monitoring

When the data collector is ready, you can configure Infoblox DNS to send us data.

To set up event forwarding via syslog, do as follows:

  1. Follow the steps in Infoblox's own guide: Getting Started with Infoblox Threat Defense.
  2. Be sure to configure the following data collector details:

    • IP address: The Sophos XDR data collector's server IP address
    • Port: 514
  3. Sophos XDR ingests Infoblox Threat Defense Data Connector logs when they're delivered as CEF over syslog to the Sophos XDR data collector. Ensure the stream includes CEF payloads where the CEF device vendor is Infoblox and the CEF device product is Data Connector. Messages must match this Data Connector CEF header pattern:

    CEF:<version>|Infoblox|Data Connector|...
    

    For field and log-type reference, see the following Infoblox documentation:

Your Infoblox DNS data should now appear in the Sophos Data Lake after validation.

Configuration notes

Keep the following in mind during Infoblox DNS configuration:

  • Sophos XDR supports CEF Name, DNS Query, and DNS Response log types. Other Data Connector CEF messages with the same vendor and product may still be received. Use Infoblox's mapping documentation for available extensions and log types: Data Connector Log Message Mapping and DNS Query/Response Log Message Mapping.
  • Some Inboblox NIOS grids forward DNS activity as classic BIND named syslog lines (wherein the text includes a named[<pid>]: process stamp, not a Data Connector CEF header). Sophos XDR handles this as follows:

    • The generic Named syslog parsers match traffic, not the Infoblox Data Connector CEF parser.
    • Events are normalized with XDR sensor type named, which is separate from the Infoblox sensor type used for Infoblox Threat Defense Data Connector CEF messages described earlier on this page.
  • You can configure multiple instances of Infoblox to send data to Sophos via the same data collector. After you finish integration, repeat the steps in this section for your other instances of Infoblox.

Additional resources

For more information on configuring Infoblox DNS, see the following documents: