Skip to content

Integrate Nozomi Guardian

You can integrate Nozomi Guardian with Sophos XDR so that it sends data to Sophos for analysis. The integration uses a data collector, which receives third-party data and sends it to the Sophos Data Lake.

Key steps

The key steps in a Nozomi Guardian integration are as follows:

  • Install and configure a data collector if you haven't already done so.
  • Configure Nozomi Guardian to send data to the data collector.

Requirements

The following is required for Nozomi Guardian configuration:

  • Check the requirements for the data collector you're using by reviewing the guides at Data collectors.

Add a Nozomi Guardian integration

To integrate Nozomi Guardian, you must first install a Sophos XDR data collector, then configure Nozomi to send logs to it.

Install and configure a data collector

Nozomi Guardian must be configured to send logs to the Sophos XDR data collector. Logs are filtered and correlated in real-time for various security event observations. Go to Data collectors and follow the guide for creating a data collector if you haven't already done so.

Configure logging and enable monitoring

When the data collector is ready, you can configure Nozomi Guardian to send us data.

To set up event forwarding via syslog, do as follows:

  1. Follow the steps in Nozomi's own guide: Nozomi Guardian User Guide.
  2. Be sure to configure the following data collector details:

    • Endpoint Configured as: Select Common Event Format (CEF).
    • To URI: Enter udp://<XDR data collector IP address>:514.

Your Nozomi Guardian data should now appear in the Sophos Data Lake after validation.

Configuration notes

Keep the following in mind during Nozomi Guardian configuration:

  • You can configure multiple instances of Nozomi to send data to Sophos via the same data collector. After you finish integration, repeat the steps in this section for your other instances of Nozomi.

Additional resources

For more information on configuring Nozomi Guardian, see the following documents: