We're thinking of using a supported Vendor 3rd Party integration for a 3rd party appliance not yet bought into Sophos Central
Currently we do not have any other vendor integrated into our Central data pool. How can we get a short demonstration on how the data integration looks like?
As far as I understood, it's mostly based on syslog. Can this data be used by MDR teams?
HILHerzog
Thanks for reaching out to the community.
We have a video that shows a demo of how Sophos Central collects data from different data sources/Integrations and shows it under a single investigation/case when an incident occurs. Demo: Sophos MDR Attack Simulation
To answer your other query, yes, all the data from the integrations is uploaded to the Sophos data lake, and that can be used by the admins or the MDR team for threat investigations. Sophos also applies AI and ML models to the data lake data and generates a detection under the threat analysis center if any suspicious activity is noticed.
Hope this helps!
In case you have any further questions related to integration or the data lake, let me know. I will try to clear your doubts.
Thanks for that video - it shows MDR can use that data.
Can this data be used by the customer?
Is my understanding correct, that this data will only be available in the area of Threat Analysis Center by the customer? So it will not be possible to query data from a 3rd party firewall with report queries in the Firewall section within Central?
Hello LHerzog,
Yup correct. Customers can use data from third-party integrations in Sophos Central. The data is primarily available in the Threat Analysis Center, where it is correlated with other security events for investigation purposes. However:
If needed, customers can use Sophos APIs or configure syslog ingestion to query and analyze third-party data externally.
Let me know if you need any further help.
Regards,
Hi LHerzog
Yes, you are correct. The data will be used in the threat analysis center, and you will not be able to query the data with report queries on the firewall. However, you will be able to query this data from the "Live Discover" using data lake queries, and the result of the queries can be exported.
We have this document where we have mentioned all the schemas and tables of the data. Using this schema, customers can make custom queries to carry out any investigation.
https://docs.sophos.com/central/References/schemas/index.html?schema=mdr_ioc_schema_docs
Regards,
Altmash