- Print
- DarkLight
Sophos Intercept X Endpoint delivers protection, stopping advanced attacks before they impact your systems. Powerful endpoint and extended detection and response (EDR/XDR) tools let your organization hunt for, investigate, and respond to suspicious activity and indicators of an attack.
Integration Method: API
Tables: Detection Finding
Sophos Endpoint Protection Configuration
Before configuring the data source in the DataBee UI, you need to set up an API client in the Sophos Central dashboard to obtain the necessary credentials. Follow these steps:
Sign in to the Sophos Central Dashboard.
Click on the General Settings option in the menu bar at the top right corner
On the General Settings window, click on the API Credentials Management option.
On the API Credentials Management window select Add Credentials.
Add the Credential Name, Description(optional) and select Service Principal Super Admin in the Role dropdown, then click on Add.
Under API credential summary you can find your Client ID and Client Secret.
DataBee Configuration
Login to the DataBee console, navigate to Data>Datasource and click on Add new Datasource.
Search for Sophos Endpoint Protection and select it.
Click on API Ingest.
Enter the required details in the form, and click on Next.
In the configuration details page, enter the following
Authorization Method: OAuth2
Client Key: Paste the Client ID generated earlier
Client Secret: Paste the Client Secret generated earlier
Click on Submit.