Skip to content

Nozomi Guardian

You can integrate Nozomi Guardian with Sophos XDR so that it sends data to Sophos for analysis.

This page gives you an overview of the integration.

Nozomi Guardian product overview

Nozomi Networks Guardian is an OT and IoT security sensor that passively monitors and analyzes network traffic to provide operational technology (OT), IoT, and industrial control system (ICS) asset visibility, threat and anomaly detection, and vulnerability assessment.

What we ingest

Sophos XDR collects Nozomi Guardian data by listening for CEF messages your Guardian sensor (or Central Management Console) forwards to a Sophos XDR data collector. The following log categories are collected:

  • Security alerts: Nozomi Guardian alert and incident events.

Event and data types

We ingest the following event and data types from Nozomi Guardian:

  • Security alerts: Nozomi Guardian alert and incident events for OT and IoT threats, anomalies, and process or protocol violations, including the alert type, severity, and affected assets. Normalized to third-party security alert telemetry.

Data provided by this integration

Data provided by Nozomi Guardian gets normalized to the following schemas:

  • thirdpartyalert

For more information about using schemas in Data Lake Search, see Schemas and logical types.

Vendor documentation