Overview
Sophos Central is an integrated management platform to help simplify the administration of multiple Sophos products, including endpoint, mobile device management (MDM), server protection, and a secure web gateway. It helps you stop spam, phishing, malware, and data loss.
Blumira’s integration allows you to retrieve event data from Sophos Central directly to your Blumira sensor to start tracking logs for threat detection and response.
Before you begin
This integration requires a Blumira sensor to be installed before you can complete the steps below. Ensure that you complete the steps in Building a Blumira sensor with Ubuntu before you continue.
Next, obtain the credentials Blumira requires to access the Sophos Central API.
To gather the Sophos credentials:
- From the Sophos Central Admin page (https://central.sophos.com) go to Global Settings > API Token Management.
- Click Add token on the top-right corner of the screen.
- Select a token name and click Save.
- In API Token Summary, check the API Access Url + Headers section, and take note of:
- url
- x-api-key
- Authorization (for example, Basic ZjAyODczYjctAxm42adfGhi3aE3…aSDF=)
Configuring Blumira
Next, you’ll need to configure your Blumira sensor to connect to the Sophos Central API, using the credentials you obtained in the steps above.
Follow these steps to add the Sophos Central module:
To add a module on an existing sensor and provide credentials:
- In Blumira, click Settings.
- Click Sensors.
- Click the sensor on which you want to add a module.
- On the detail page for the sensor, scroll down and click Add Module.
- In the Add New Module window, select the relevant module.
- Enter the credentials that you gathered in previous steps.
- (Optional) Type a name for this log deployment in the Log Source Name box.
Note: Use alphanumeric characters, periods, and hyphens. Spaces and underscores are not allowed. This name will appear in the "device_address" column in the results of your event data queries. If you add more modules to collect logs for other integrations, this name will help you to identify them. - Click Install.