Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

List of possible log Events for SIEM integration

I need to integrate the Sophos Central events into our SIEM. I need to create regex for the type of events like:

  • Event::Endpoint::UpdateSuccess
  • Event::Endpoint::WebControlViolation

Where can I find the list of event types?



This thread was automatically locked due to age.
Parents Reply
  • Brent, has the parsing/MPE rule you've written for LogRhythm been functioning well since your last post?  I'm currently in a position where we want to start collecting our Sophos Central events, as well.  Would you be willing to share the regex you're using?  Or maybe export your MPE rule and share?

Children