Skip to content

Integrate Rubrik

You can integrate Rubrik with Sophos XDR so that it sends data to Sophos for analysis.

Key steps

The key steps in a Rubrik integration are as follows:

  • Get details of your Rubrik Security Cloud service.
  • Create an API application and a service user.
  • Configure the integration in Sophos XDR.

Requirements

The following is required for Rubrik configuration:

  • Access to the Rubrik Security Cloud console.

Add a Rubrik integration

To integrate Rubrik, you must first gather certain details from Rubrik, then provide them in Sophos XDR.

Get the API details from Rubrik

To get the Rubrik API details you need for integration, do as follows:

  1. Log in to Rubrik Security Cloud.
  2. Click the Square grid icon and select Settings.
  3. In Settings, go to Users and Access > Service Accounts.
  4. In Service Accounts, click Add Service Account.

    The Service Account Details assistant starts.

  5. Enter a Name and Description for the service account.

  6. Click Next.

    The Roles assistant starts.

  7. Select the roles to be assigned to the service account.

  8. Click Add.

    Rubrik Security Cloud creates the service account, then displays the client credentials and Access Token URI.

  9. Copy the Client ID and Client Secret. You'll need to use them later in Sophos XDR.

  10. Pull the Base URL from the Access Token URI, in the following form: https://<account>.my.rubrik.com. You'll need to use it later in Sophos XDR.

Next, you configure an integration in Sophos XDR.

Configure the integration in Sophos XDR

To integrate Rubrik with Sophos XDR, do as follows:

  1. In Sophos Fusion, go to Security Operations > Integrations > Marketplace.
  2. Click Rubrik.

    The Rubrik page opens. You can configure integrations here and see a list of any you've already configured.

  3. In Configured integrations, click Add new.

  4. In Add an integration, do as follows:

    1. Enter a name for the integration.
    2. Enter the following details you got from Rubrik:

      • Base URL
      • Client ID

        Note

        Make sure you enter the Client ID in the format client|<UUID>. For example, client|a5cc86be-5f95-42c3-9f3e-540b8e79dcdc.

      • Client Secret

  5. Click Done.

The new integration appears under Configured integrations. If its status icon is a green tick, your data should appear in the Sophos Data Lake after validation.

Additional resources

For more information on configuring Rubrik, see the following documents: