Skip to content

Microsoft Azure Application Gateway

You can integrate Microsoft Azure Application Gateway with Sophos XDR so that it sends data to Sophos for analysis.

This page gives you an overview of the integration.

Microsoft Azure Application Gateway product overview

Azure Application Gateway is a Layer 7 web traffic load balancer that manages traffic to web applications, providing URL-path and host-based routing, SSL/TLS termination, and autoscaling, with an integrated Web Application Firewall (WAF) that protects applications from common exploits and vulnerabilities.

What we ingest

Sophos XDR collects Azure Application Gateway logs via Azure Monitor: you enable diagnostic settings on the gateway and stream the log categories to an Azure Event Hub, which Sophos XDR ingests. The following log categories are collected:

  • Access activity: Application Gateway access logs for the web requests it routes.
  • Firewall (WAF) activity: Application Gateway Web Application Firewall logs.

Event and data types

We ingest the following event and data types from Azure Application Gateway:

  • Access activity: Application Gateway access-log web requests, including the client, URL, backend target, and response status. Normalized to HTTP telemetry.
  • Firewall (WAF) activity: Application Gateway Web Application Firewall events, including the matched rule, message, and action. Normalized to HTTP telemetry.

Data provided by this integration

Data provided by Azure Application Gateway gets normalized to the following schemas:

  • http

For more information about using schemas in Data Lake Search, see Schemas and logical types.

Vendor documentation