跳至正文

Sophos Integration

Overview

This integration collects logs from both Sophos XGS Firewall and Intercept X Endpoint via Sophos Central. A single API covers firewall and endpoint events.

Supported products: Sophos XGS Firewall, Intercept X (Endpoint), Sophos Central


Prerequisites

  • A KYRA MDR Collector installed and running (Installation Guide)
  • Sophos Central admin account with API access
  • For syslog: network connectivity from XGS Firewall to the collector on port 514

Configuration

The Sophos Central SIEM API provides unified access to firewall and endpoint events.

  1. Log in to Sophos Central
  2. Navigate to Settings > API Credentials
  3. Create API credentials and note the Client ID and Client Secret
  4. Provide these credentials to KYRA MDR during integration setup
GET https://api.central.sophos.com/siem/v1/alerts
Authorization: Bearer <token>

Option 2: Syslog (XGS Firewall Only)

  1. Log in to the XGS Firewall console
  2. Navigate to System Services > Log Settings
  3. Add a syslog server pointing to your KYRA Collector IP on port 514
device="SFW" date=2026-03-20 time=10:30:00 log_type="Firewall" log_component="Firewall Rule"

Collected Log Types

Log TypeSecurity UsePriority
Firewall trafficNetwork flow and policy monitoringHigh
IPS eventsIntrusion detectionCritical
VPNRemote access monitoringHigh
Web FilterWeb access policy enforcementMedium
Application ControlApplication visibilityMedium
Endpoint AV (Intercept X)Malware detection on endpointsCritical
EDR/XDR alertsAdvanced threat detectionCritical
Admin activityConfiguration change auditingHigh

Troubleshooting

API Connection Issues

  1. Verify the Client ID and Client Secret are correct
  2. Ensure the API credentials have SIEM permissions enabled
  3. Check that outbound HTTPS access to api.central.sophos.com is not blocked

No Syslog Logs

  1. Verify the syslog server IP and port in XGS settings
  2. Ensure port 514 is open between the firewall and collector

For additional help, contact kyra@seekerslab.com.