Reflexion will be End-of-life on March 31,2023. See Sophos Reflexion EoL FAQs to learn more.
The script siem.py is very useful to retrieve alerts and actions on Sophos Central, but it is unable to collect data from XDR.
Is it possible to "empower" it to read XDR data? SIEM would have a complete visibility on activities done on the infrastructure and the security team would have a complete view to track malicious activities.
To access that sort of data, we have another API documented here: https://developer.sophos.com/
RichardP
Program Manager, Support Readiness | CISSP | Sophos Technical SupportSupport Videos | Product Documentation | @SophosSupport | Sign up for SMS AlertsIf a post solves your question use the 'Verify Answer' link.
Hi. Thank you for your answer.
I perfectly know how Sophos API works, but SIEM Integration API does not collect XDR data.
I would like to ask a feature enhancement to let this integration collect XDR data as well.
regards
Currently, it’s not possible to replicate all the data stored in the Data Lake onto a SIEM or local environment, it's only possible to query the data. I suggest reaching out to your account manager to inquire if there’s anything present on the product roadmap that may fulfil your needs.