Skip to main content
yujames
Staff
Staff
October 25, 2019

Technical Tip: How to configure Sophos central URI

  • October 25, 2019
  • 0 replies
  • 1949 views

Description

 

This article describes how to configure Sophos Central to pick up logs from Sophos Central.

Scope

 

FortiSIEM v7.4.x.

Solution

 

To collect data from Sophos Central, the following is necessary:
  1. Tenant ID.
  2. Client ID.
  3. Client Secret.
  4. Sophos Central URL.

 

 
The Tenant ID, Client ID, and Client secret provided from Sophos Central will be respectively configured within the credentials page.
 
The Sophos URL is as follows: https://api.central.sophos.com
 
Note:
Depending on the account creation, Sophos may provide a different API endpoint (e.g. api1.central.sophos.com would also work).

 

To apply the configuration provided by Sophos:
  1. Admin -> Setup -> Credentials -> Step 1 -> New.
 
sophos_screen.png

 


 

  1. Add the address to the 2nd step within the credential's tab under Admin -> Setup -> Credentials -> Step 2 -> New.
 
Stephen_G_1-1747001095592.png

 

  1. Save this and select to Test Connectivity without Ping:

 

Stephen_G_2-1747001149665.png

 

  1. Verify that this entry has been scheduled for event pulling. Admin -> Setup -> Pull Events.

 

Stephen_G_3-1747001188499.png
 
Related document: