Nozomi Guardian
You can integrate Nozomi Guardian with Sophos XDR so that it sends data to Sophos for analysis.
This page gives you an overview of the integration.
Nozomi Guardian product overview
Nozomi Networks Guardian is an OT and IoT security sensor that passively monitors and analyzes network traffic to provide operational technology (OT), IoT, and industrial control system (ICS) asset visibility, threat and anomaly detection, and vulnerability assessment.
What we ingest
Sophos XDR collects Nozomi Guardian data by listening for CEF messages your Guardian sensor (or Central Management Console) forwards to a Sophos XDR data collector. The following log categories are collected:
- Security alerts: Nozomi Guardian alert and incident events.
Event and data types
We ingest the following event and data types from Nozomi Guardian:
- Security alerts: Nozomi Guardian alert and incident events for OT and IoT threats, anomalies, and process or protocol violations, including the alert type, severity, and affected assets. Normalized to third-party security alert telemetry.
Data provided by this integration
Data provided by Nozomi Guardian gets normalized to the following schemas:
thirdpartyalert
For more information about using schemas in Data Lake Search, see Schemas and logical types.