Skip to content

McAfee ePO

You can integrate McAfee ePO with Sophos XDR so that it sends data to Sophos for analysis.

This page gives you an overview of the integration.

McAfee ePO product overview

McAfee ePolicy Orchestrator (ePO) is a centralized security management platform that unifies endpoint security, data loss prevention, and threat intelligence, letting security teams manage policies, monitor threats, and respond to events across managed endpoints from a single console.

What we ingest

Sophos XDR collects McAfee ePO syslog data by listening for messages your ePO server forwards to a Sophos XDR data collector. The following log categories are collected:

  • Threat and malware detections: Endpoint threat and anti-malware detections, including file, process, registry, persistence, and user context.
  • Network threats: Network-based threat detections.
  • Web threats: Web-based (HTTP) threat detections.
  • Data loss prevention: DLP policy violations.

Event and data types

We ingest the following event and data types from McAfee ePO:

  • Threat and malware detections: Endpoint threat and anti-malware detections, enriched with the affected file, process, registry, persistence, and user context where present. Normalized to antivirus, process, registry, persistence, and authentication telemetry.
  • Network threats: Network-based threat detections, including the source, destination, and detection. Normalized to third-party security alert telemetry.
  • Web threats: Web-based (HTTP) threat detections, including the URL and action. Normalized to HTTP and third-party security alert telemetry.
  • Data loss prevention: DLP policy violations, including the rule and action. Normalized to third-party security alert telemetry.

Data provided by this integration

Data provided by McAfee ePO gets normalized to the following schemas:

  • antivirus
  • auth
  • http
  • persistence
  • process
  • registry
  • thirdpartyalert

For more information about using schemas in Data Lake Search, see Schemas and logical types.

Vendor documentation