Sophos Logs

Connecting Sophos logs to your Panther Console

Overview

Panther supports ingesting Sophos logs via common Data Transport options: Amazon Web Services (AWS) S3 and SQS.

How to onboard Sophos logs to Panther

To connect these logs into Panther:

  1. In the left-hand navigation bar of your Panther Console, click Configure > Log Sources.

  2. Click Create New.

  3. Search for the log type you want to onboard, then click its tile.

  4. Select the data transport method you wish to use for this integration, then follow Panther's instructions for configuring the method:

  5. Configure Sophos to push logs to the Data Transport source.

    • See the Sophos documentation for instructions on pushing logs to your selected Data Transport source.

Supported log types

Sophos.Central

Sophos Central events.

Reference: Sophos Documentation on Central API Events.

Last updated

Was this helpful?