Sophos Endpoint Protection Solution

Solution: Sophos Endpoint Protection

Sophos Endpoint Protection Logo

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Solutions Index


Attribute Value
Publisher Microsoft Corporation
Support Tier Microsoft
Support Link https://support.microsoft.com/
Categories domains
Version 3.0.8
Author Microsoft - support@microsoft.com
First Published 2021-07-07
Last Updated 2026-04-17
Solution Folder Sophos Endpoint Protection
Marketplace Azure Marketplace · Popularity: 🟢 High (85%)

The Sophos Endpoint Protection solution provides the capability to ingest to ingest Sophos events and Sophos alerts into Microsoft Sentinel. Refer to Sophos Central documentation for more information.

Underlying Microsoft Technologies used:

This solution takes a dependency on the following technologies, and some of these dependencies either may be in Preview state or might result in additional ingestion or operational costs:

a. Azure Monitor HTTP Data Collector API

b. Azure Functions

c. Codeless Connector Platform (CCP)

Contents

Data Connectors

This solution provides 2 data connector(s):

🔶 CLv1: This connector ingests into a table that uses the legacy Custom Log V1 schema format with type-suffixed column names (e.g. _s, _d, _b, _t, _g). Note: identification is based on column name suffixes which are also permitted in CLv2, so this classification may not always be accurate.

Tables Used

This solution uses 3 table(s):

Table Used By Connectors Used By Content
SophosEPAlerts_CL Sophos Endpoint Protection (via Codeless Connector Platform) -
SophosEPEvents_CL Sophos Endpoint Protection (via Codeless Connector Platform) -
SophosEP_CL 🔶 [DEPRECATED] Sophos Endpoint Protection (using Azure Function) -

🔶 CLv1: This table uses the legacy Custom Log V1 schema format with type-suffixed column names (e.g. _s, _d, _b, _t, _g). Note: identification is based on column name suffixes which are also permitted in CLv2, so this classification may not always be accurate.

Content Items

This solution includes 1 content item(s):

Content Type Count
Parsers 1

Parsers

Name Description Tables Used
SophosEPEvent - -

Release Notes

Version Date Modified (DD-MM-YYYY) Change History
3.0.8 14-04-2026 Deprecate Sophos Endpoint Protection (using Azure Function)
3.0.7 24-03-2026 Sophos Endpoint Protection (via Codeless Connector Platform)
3.0.6 23-10-2025 Updated the solution to be compatible with tool changes for the connection name.
3.0.5 21-08-2024 Data Connector [Sophos Endpoint Protection (using REST API)] Globally Available
3.0.4 01-07-2024 Update files for CCP Connector to fix the connectivity
3.0.3 25-04-2024 Repackaged for parser issue with old names
3.0.2 12-04-2024 Repackaged for parser fix in solution package
3.0.1 12-03-2024 Updated Sophos Endpoint Function App and Parser
Added new CCP Data Connector
3.0.0 14-08-2023 Manual deployment instructions updated for Data Connector

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Solutions Index