Microsoft Windows Event Log
You can integrate Microsoft Windows Event Log with Sophos XDR so that it sends data to Sophos for analysis.
This page gives you an overview of the integration.
Microsoft Windows Event Log product overview
Microsoft Windows Event Log is the native logging framework in Windows that records security, system, and application events across Windows hosts and domain controllers. Its Security channel captures audit events—successful and failed logons, privilege and resource use, account and policy changes, and process activity—as defined by Windows audit policy.
What we ingest
A Sophos XDR data collector accepts Windows Event Log data in the Snare-over-syslog format, forwarded from your Windows hosts by NXLog, Snare Enterprise, or a compatible agent. Depending on which events your hosts are configured to forward, this integration can collect the following log categories:
- Authentication and account activity: Security-auditing logon and logoff events and Active Directory account, group, and policy changes.
- Process activity: Process creation and object-access events.
- Malware detections: Microsoft Defender Antivirus events.
- Configuration and management: Scheduled tasks, system time, and administrative change events.
- Directory object audit: Directory-service object-access audit events.
- Threat and encrypted-channel events: Attack detections and certificate or encrypted-channel events.
- Network activity1: Windows Filtering Platform connection events.
Event and data types
We ingest the following event and data types from Microsoft Windows Event Log:
- Authentication and account activity: Windows Security Auditing logon and logoff events (for example, Event IDs
4624and4625), credential and privilege use, and Active Directory account, group, and policy changes, with the user, host, and result. Normalized to authentication telemetry. - Process activity: Process creation (Event ID
4688) and object-access events (Event ID4663), including the process, command line, and target. Normalized to process telemetry. - Malware detections: Microsoft Defender Antivirus detection and remediation events, including the threat and action. Normalized to antivirus telemetry.
- Configuration and management: Scheduled-task (Event IDs
4698–4702), system-time (Event ID4616), and other administrative configuration-change events. Normalized to management event telemetry. - Directory object audit: Directory-service object-access operations (Event ID
4662). Normalized to cloud audit telemetry. - Threat and encrypted-channel events: Attack detections such as replay attacks (Event ID
4649) and certificate or encrypted-channel events. Normalized to third-party security alert and encrypted-traffic telemetry. - Network activity1: Windows Filtering Platform connection and firewall events (for example 5156), including source and destination addresses and ports. Normalized to netflow telemetry.
Data provided by this integration
Data provided by Microsoft Windows Event Log gets normalized to the following schemas:
antivirusauthcloudauditencryptmanagementeventnetflow1processthirdpartyalert
For more information about using schemas in Data Lake Search, see Schemas and logical types.
Vendor documentation
-
Netflow telemetry is only available with a Sophos Next-Gen SIEM subscription. See Sophos Next-Gen SIEM overview. ↩↩↩