Sophos XDR Integration via API

SOPHOS XDR INTEGRATION via API

This integration lets Logsign pull security alerts and events from Sophos Central using the Sophos Central SIEM API. Sophos Central is a cloud-hosted console (accessed at central.sophos.com), not an on-premises appliance, so there is no local IP address to configure on the Sophos side.

Important: use Tenant-level API credentials, not Partner-level credentials. Sophos Central lets you generate API credentials in two different places: from a Partner/MSP dashboard (which manages multiple customer tenants), or from within a single Tenant account. Logsign's integration expects Tenant-scoped credentials. If you generate a Partner-scoped credential instead, Logsign cannot resolve it to a single tenant and the integration will fail. Make sure you are logged in to the specific Sophos Central tenant you want to collect logs from (not the Partner Dashboard) before generating the credential.

Use least privilege. Logsign only reads alerts and events from Sophos through this integration; it does not manage users, endpoints, or policies. The Service Principal Read-Only role is sufficient. Avoid Super Admin or Management roles unless you have a separate reason to need them.

Note: The first time you click API Credentials Management you must read and accept the terms and conditions of use.

To add credentials, do as follows:

  1. Log in to Sophos Central as an administrator of the tenant you want to integrate (not the Partner Dashboard).
  2. Go to Settings & Policies> API Credentials Management.
  3. Click Add Credential and give the credential a name and description.
  4. Choose Service Principal Read-Only as the role. The other available roles are:
    • Service Principal Super Admin: full API access with CRUD (Create Read Update Delete) capabilities and access to queries.
    • Service Principal Management: can view and manage admins, roles, endpoints, and security policies, but cannot run or view queries.
    • Service Principal Forensics: can create, view, run, and delete Live Discover queries.
    • Service Principal Active Directory Sync: only for Active Directory synchronization, nothing else.
  5. Click Add.

This generates the credential, together with a Client ID and a Client Secret.

  1. Copy the Client ID and Client Secret immediately.

Note: You can only see the Client Secret once.

After these processes, you'll add the source to view logs from the Sophos device from the Logsign SIEM product.

Open Logsign and click on the "+ Device" button under the Sources tab, which is then clicked on the Settings -> Data Collection tab in the menu bar on the top of the page. In the Source Type Selection page, choose API as the method and Sophos XDR is selected as Provider information. There is some information about the source that you want to add on the page.

mceclip1.png

Fill in the Client ID and Client Secret from the credential you generated, then click "Check Connection." Logsign automatically determines your tenant ID and data region from these credentials; you do not need to enter them manually.

On the page that opens, fill in the remaining information (Device Name, Tag, Groups, Role, etc.) and complete the integration by clicking "Save."

Troubleshooting: if Check Connection or the source fails with an authentication or tenant-related error, the most common cause is that the credential was generated from the Partner Dashboard instead of from within the specific tenant. Regenerate the credential from inside the tenant's own Sophos Central account (Settings & Policies > API Credentials Management) and try again.

Was this article helpful?
1 out of 1 found this helpful

Articles in this section

See more
Become a Certified Logsign User/Administrator
Sign-up for Logsign Academy and take the courses to learn about Logsign USO Platform in detail. Enjoy the courses, and get your badges and certificates. In these courses, you'll learn how to use Logsign in your work and add value to your career.
Visit Our Blog
Our Logsign USO Platform illustrate our expertise. So do the blog. Through our blog posts, deepen your knowledge on various SecOps topics or get updated about important news & modern approaches for cybersecurity. Get into the habit of reading valuable information provided by Logsign. Be a step ahead.