Skip to content

Files

Latest commit

 

History

History
3 lines (2 loc) · 281 Bytes

README.md

File metadata and controls

3 lines (2 loc) · 281 Bytes

Sophos-XDR SIEM integration

This is a script for querying the Sophos XDR datalake. You only need valid API credentials. The SQL query is hardcoded and based on the "sophos_events_windows" template. The script creates a JSON log that is ready to be shipped to any SIEM solution.