Linux servers
You can integrate Linux servers with Sophos XDR so that they send data to Sophos for analysis.
This page gives you an overview of the integration.
Linux servers product overview
Linux servers record system, security, and service activity through the operating system's syslog logging framework. Common security-relevant sources include authentication and privilege-escalation events (SSH and sudo), DNS resolver activity (BIND/named), and system and service daemon events.
What we ingest
Sophos XDR collects Linux server data by listening for syslog messages your Linux hosts forward to a Sophos XDR data collector. The following log categories are collected:
- Authentication and privilege use: SSH and sudo authentication and privilege-escalation events.
- DNS activity: BIND/named DNS query events.
- System management: System and service management events.
Event and data types
We ingest the following event and data types from Linux servers:
- Authentication and privilege use: SSH (sshd) and sudo authentication and privilege-escalation events, including the user, source, and result. Normalized to authentication telemetry.
- DNS activity: DNS resolver (BIND/named) query and response events, including the queried domain. Normalized to DNS query telemetry.
- System management: System and service daemons and configuration events. Normalized to management event telemetry.
Data provided by this integration
Data provided by Linux servers gets normalized to the following schemas:
authdnsquerymanagementevent
For more information about using schemas in Data Lake Search, see Schemas and logical types.