McAfee ePO
You can integrate McAfee ePO with Sophos XDR so that it sends data to Sophos for analysis.
This page gives you an overview of the integration.
McAfee ePO product overview
McAfee ePolicy Orchestrator (ePO) is a centralized security management platform that unifies endpoint security, data loss prevention, and threat intelligence, letting security teams manage policies, monitor threats, and respond to events across managed endpoints from a single console.
What we ingest
Sophos XDR collects McAfee ePO syslog data by listening for messages your ePO server forwards to a Sophos XDR data collector. The following log categories are collected:
- Threat and malware detections: Endpoint threat and anti-malware detections, including file, process, registry, persistence, and user context.
- Network threats: Network-based threat detections.
- Web threats: Web-based (HTTP) threat detections.
- Data loss prevention: DLP policy violations.
Event and data types
We ingest the following event and data types from McAfee ePO:
- Threat and malware detections: Endpoint threat and anti-malware detections, enriched with the affected file, process, registry, persistence, and user context where present. Normalized to antivirus, process, registry, persistence, and authentication telemetry.
- Network threats: Network-based threat detections, including the source, destination, and detection. Normalized to third-party security alert telemetry.
- Web threats: Web-based (HTTP) threat detections, including the URL and action. Normalized to HTTP and third-party security alert telemetry.
- Data loss prevention: DLP policy violations, including the rule and action. Normalized to third-party security alert telemetry.
Data provided by this integration
Data provided by McAfee ePO gets normalized to the following schemas:
antivirusauthhttppersistenceprocessregistrythirdpartyalert
For more information about using schemas in Data Lake Search, see Schemas and logical types.