Microsoft Azure Firewall
You can integrate Microsoft Azure Firewall with Sophos XDR so that it sends data to Sophos for analysis.
This page gives you an overview of the integration.
Microsoft Azure Firewall product overview
Azure Firewall is a cloud-native, managed network firewall service that protects Azure Virtual Network resources, providing stateful Layer 3 to Layer 7 filtering of inbound, outbound, and east-west traffic through application and network rules, URL filtering and web categories, and an intrusion detection and prevention system (IDPS).
What we ingest
Sophos XDR collects Azure Firewall logs via Azure Monitor: you enable diagnostic settings on the firewall and stream the log categories to an Azure Event Hub, which Sophos XDR ingests. The following log categories are collected:
- Application rule activity: Application-rule (Layer 7) and URL-filtering traffic.
- IDPS and threat intelligence alerts: IDPS signature and threat-intelligence detections.
- DNS proxy activity: DNS proxy queries.
Event and data types
We ingest the following event and data types from Microsoft Azure Firewall:
- Application rule activity: Application-rule (Layer 7) and URL-filtering traffic decisions, including the URL, action, and endpoints. Normalized to HTTP telemetry.
- IDPS and threat intelligence alerts: IDPS signature detections and threat-intelligence matches, including the signature, action, and endpoints. Normalized to third-party security alert telemetry.
- DNS proxy activity: Azure Firewall DNS proxy queries and responses, including the queried domain. Normalized to DNS query telemetry.
Data provided by this integration
Data provided by Microsoft Azure Firewall gets normalized to the following schemas:
dnsqueryhttp
thirdpartyalert
For more information about using schemas in Data Lake Search, see Schemas and logical types.