Hello,
We are working on analyzing our Sophos Central Event data, now it is a manual process in which we export the data to a csv file manually through the interface. Is there any automated way to do this? Other cloud services offer methods of extracting logs for SIEM consumption or APIs etc. I read in the FAQ that the API is a future item. I don't even see a way to schedule reports. Anyone else run into this need or come up with any solutions?
Thanks
HI Jpf ,
Currently, we do not have such feature available with us at the moment . but for all members who wish to add a feature in the current product please port your idea on http://ideas.sophos.com .
For such feature request please vote on an existing ideas or Post any new Idea and with Enough votes this would be considered in the next release. We encourage everyone to post your idea or vote for an existing feature request . Your Vote Counts .
For this feature request please follow the link below .
http://ideas.sophos.com/forums/285723-sophos-endpoint?query=reports%20central
Thanks and Regards
Aditya Patel | Network and Security Engineer.
Regards,
Aditya Patel
Global Escalation Support Engineer | Sophos Technical Support
Knowledge Base | @SophosSupport | Sign up for SMS Alerts
If a post solves your question use the 'This helped me' link.
Hi JPF,
We have just recently released a Sophos Central update which introduced SIEM API, the following knowledge base articles will explain how it works.
Event Data can be downloaded in json, cef, and splunk formats
Leon Friend
Sophos Sales Engineer
Sophos XG Firewall - Certified Architect, Sophos Certified Engineer, Cyberoam CCNSE, Cyberoam CCNSP
Am I understanding this correctly? This is available for CUSTOMERS only? Not for Partners? I can't get an aggregate view on all my managed customers?
Hi Tim,
Yes the security is locked to individual end user accounts, you could however set your SIEM up so that it collects data from each customer account.
Leon Friend
Sophos Sales Engineer
Sophos XG Firewall - Certified Architect, Sophos Certified Engineer, Cyberoam CCNSE, Cyberoam CCNSP
Hi Leon,
to piggy back of this old question, is there a way to use the API to pull down the "Active user" report?
I can see no way to do this from the documents.
Many thanks,
Patricks
We do have the options available to Schedule the reports as suggested in this article where you can select the option "Send an email with a report attached (not secure)".
Shweta
Hi Shweta,
Thanks for looking at this. Unfortunately what I was after was a method of getting the file in an automated way, so it could be ingested by another system for Licence reporting purposes.
I think email would not be suitable for this need.
Many thanks
Patrick
This can be achieved by SIEM integration as mentioned above in this thread. I would suggest you contact your partner in case you require further assistance with SIEM integration.
Shweta