Sophos Community
Sophos Community
  • Site
  • User
  • Site
  • Search
  • User
  • Community & Product Forums
    • Intercept X Endpoint
    • Sophos Firewall
    • Sophos Central
    • Sophos Factory
    • Sophos Mobile
    • Sophos Cloud Optix
    • Sophos Sensor
    • Sophos Switch
    • Sophos Wireless
    • Sophos Email
    • UTM Firewall
  • Community Blogs & Events
    • Sophos Community Blog
    • Community Security Blog
    • Product Documentation Blog
    • Application Control
  • Getting Started
  • Sophos Partners
    • Sophos Partners Group
  • Member Recognition
    • Community Leaderboards
  • Sophos Techvids
  • Product Documentation
    • Visit docs.sophos.com
  • Support Portal
    • Sophos.com
  • More
  • Cancel
EDR Data Lake EAP
  • Intercept X Endpoint
  • More
EDR Data Lake EAP

Files

  • Announcements
  • Discussions
  • Files
  • Queries
  • More
  • Cancel
  • New
EDR Data Lake EAP requires membership for participation - click to join
  • View slideshow
  • RSS
  • More
  • Cancel

XDR & EDR Data Lake EAP Known Issues doc

LINUX Schema in EXCEL

MAC Schema in EXCEL

Windows Schema in excel

Sophos Endpoint Data Lake Schema

Sophos Windows Extension Schema

OSQuery 4.5.1 Schema

Endpoint Query Pack

query to list endpoint tables in the data lake

query to list recently installed applications

query to list IE extensions

query to list homebrew packages

query to list firefox addons

query to list deb packages

query to list chrome extensions

query to list executable file changes

query to list browser plugins

QUERY to list arp_cache info

Joining the EDR Data Lake Early Access Program

DATA LAKE Schema - Endpoint Data

Unfiltered HTML
  • Getting started
  • Legal
  • Privacy
  • Cookies

© 1997 - 2022 Sophos Ltd. All rights reserved.