↳ GitHub sourceConnector

Sophos Endpoint Protection (via Codeless Connector Platform)

Description

The [Sophos Endpoint Protection](https://www.sophos.com/en-us/products/endpoint-antivirus.aspx) data connector provides the capability to ingest [Sophos events](https://developer.sophos.com/docs/siem-v1/1/routes/events/get) and [Sophos alerts](https://developer.sophos.com/docs/siem-v1/1/routes/alerts/get) into Microsoft Sentinel. Refer to [Sophos Central Admin documentation](https://docs.sophos.com/central/Customer/help/en-us/central/Customer/concepts/Logs.html) for more information.
Declared author / publisher
Microsoft

Declared sources

Metadata from the source file. No dependencies inferred from KQL.

Data types

Declared permissions

Read and Write permissions are required.
Workspace
Workspace
Sophos Endpoint Protection API access
Access to the Sophos Endpoint Protection API through a service principal is required.

Connector instructions

Content published in the repository. Refer to the original file for all parameters.

Follow [Sophos instructions](https://developer.sophos.com/getting-started-tenant) to create a service principal with access to the Sophos API. It will need the Service Principal ReadOnly role. Through those instructions, you should get the Client ID, Client Secret, Tenant ID and data region. Fill the form bellow with that information.
Sophos Tenant ID
Sophos Tenant Data Region
Connect to Sophos Endpoint Protection API to start collecting event and alert logs in Microsoft Sentinel

Related content

Links established from declared identifiers and solution manifests.

Source provenance

GitHub

Displayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.

Source identifier
SophosEndpointProtectionCCPDefinition
Additional source files 2Solutions/Sophos Endpoint Protection/Data Connectors/SophosEP_ccp/SophosEP_DataConnectorDefinition.jsonsource ↗Solutions/Sophos Endpoint Protection/Data/Solution_EP.jsonsolution-membership ↗
GSTEP / CATALOG TRACKING

Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 05:49 UTC

GSTEP sync dates, separate from the source content’s publication dates.