We are new customers to Sophos Endpoint. I'm trying to help our Infosec people set up QRadar to query the SQL server for Sophos logging. However, the IBM documentation for the setup is out-of-date and Sophos provides no support for the QRadar setup, from what I can tell.
I have found that there is no more Reporting Interface installation - the tables it used to install are already included with the Sophos521 database. However, QRadar wants to query a table named 'vEventsCommonData' which doesn't exist. There is, however, a VIEW named that, but QRadar throws this error message:
Protocol Provider Thread: class
com.q1labs.semsources.sources.jdbc.JdbcEventConnector111] java.sql.SQLException:
Invalid object name 'vEventsCommonData'.
QRadar is set up to use my SophosSQL account, which has the dbcreator permission that Sophos says it needs. Is it possible that this account needs some other permissions? Or maybe QRadar needs a special config to query the VIEW instead of the TABLE?
Searching for info on Sophos & QRadar yields next-to-nothing, so I hope someone here knows how to configure it.
Thanks!
This thread was automatically locked due to age.