Does anyone have the API working with getting the Web Gateway logs? I am assuming I will need a modified API but couldn't find any reference.
This thread was automatically locked due to age.
Hi Brent,
Sophos Central has secured APIs available for customers. These allow the retrieval of event and alert data from Sophos Central(For web gateway included), for integration with SIEM (Security Information and Event Management) .
Please refer the below link for further details.
Sophos Central APIs: How to send alert and event data to your SIEM
Hope it helps.
Regards,
Gowtham Mani
Community Support Engineer | Sophos Technical Support
Knowledge Base | @SophosSupport | Sign up for SMS Alerts
If a post solves your question use the 'This helped me' link.
I guess I should have stated I have the API working for 8 Central instances. I am getting all the endpoint logs, but I am assuming Web Gateway is some other type of classification or my siem.py needs to be modified to allow for Web Gateway.