Solution: Sophos Endpoint Protection
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊
| Attribute | Value |
|---|---|
| Publisher | Microsoft Corporation |
| Support Tier | Microsoft |
| Support Link | https://support.microsoft.com/ |
| Categories | domains |
| Version | 3.0.8 |
| Author | Microsoft - support@microsoft.com |
| First Published | 2021-07-07 |
| Last Updated | 2026-04-17 |
| Solution Folder | Sophos Endpoint Protection |
| Marketplace | Azure Marketplace · Popularity: 🟢 High (85%) |
The Sophos Endpoint Protection solution provides the capability to ingest to ingest Sophos events and Sophos alerts into Microsoft Sentinel. Refer to Sophos Central documentation for more information.
Underlying Microsoft Technologies used:
This solution takes a dependency on the following technologies, and some of these dependencies either may be in Preview state or might result in additional ingestion or operational costs:
a. Azure Monitor HTTP Data Collector API
c. Codeless Connector Platform (CCP)
This solution provides 2 data connector(s):
🔶 CLv1: This connector ingests into a table that uses the legacy Custom Log V1 schema format with type-suffixed column names (e.g.
_s,_d,_b,_t,_g). Note: identification is based on column name suffixes which are also permitted in CLv2, so this classification may not always be accurate.
This solution uses 3 table(s):
🔶 CLv1: This table uses the legacy Custom Log V1 schema format with type-suffixed column names (e.g.
_s,_d,_b,_t,_g). Note: identification is based on column name suffixes which are also permitted in CLv2, so this classification may not always be accurate.
This solution includes 1 content item(s):
| Content Type | Count |
|---|---|
| Parsers | 1 |
| Name | Description | Tables Used |
|---|---|---|
| SophosEPEvent | - | - |
| Version | Date Modified (DD-MM-YYYY) | Change History |
|---|---|---|
| 3.0.8 | 14-04-2026 | Deprecate Sophos Endpoint Protection (using Azure Function) |
| 3.0.7 | 24-03-2026 | Sophos Endpoint Protection (via Codeless Connector Platform) |
| 3.0.6 | 23-10-2025 | Updated the solution to be compatible with tool changes for the connection name. |
| 3.0.5 | 21-08-2024 | Data Connector [Sophos Endpoint Protection (using REST API)] Globally Available |
| 3.0.4 | 01-07-2024 | Update files for CCP Connector to fix the connectivity |
| 3.0.3 | 25-04-2024 | Repackaged for parser issue with old names |
| 3.0.2 | 12-04-2024 | Repackaged for parser fix in solution package |
| 3.0.1 | 12-03-2024 | Updated Sophos Endpoint Function App and Parser Added new CCP Data Connector |
| 3.0.0 | 14-08-2023 | Manual deployment instructions updated for Data Connector |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊