Integrate with Microsoft Azure Sentinel
Sophos Cloud Optix can send alert data to your Microsoft Azure Sentinel workspace.
To integrate with Microsoft Azure Sentinel, do as follows:
When integration is turned on, Sophos Cloud Optix events appear in your Sentinel workspace in Microsoft Azure. You can query Sophos Cloud Optix data in Microsoft Azure Sentinel to examine the most relevant events. For more details, see Example Microsoft Azure Sentinel queries.