Sophos Central sample event message
The following sample events are from the Sophos Central when you use the Sophos Central protocol.
Event - Endpoint
In the following sample event message, the event indicates the results of an action that returns the details of that Sophos Central generated event.
{"source":"n/a","when":"2024-04-23T16:22:10.159Z","severity":"low","type":"Event::Endpoint::UpdateRebootRequired","location":"AA1AAAA-1234AAA1","id":"111111aa-1a0a-11aa-a111-1111a1a01a11","group":"UPDATING","endpoint_id":"111111aa-1a0a-11aa-a111-1111aaaaaaa","endpoint_type":"server","customer_id":"111111aa-1a0a-11aa-a111-1111a1a01a11","created_at":"2024-04-23T16:22:10.170Z","source_info":{"ip":"10.0.0.1"},"name":"Reboot to complete update; computer stays protected in the meantime"}
QRadar field name | Highlighted payload field name |
---|---|
Event ID | type |
Source IP | source_info.ip |
Device Time | created at |
Severity | severity |
Alert - Endpoint
In the following sample event message, the event indicates the results of an action that returns the details of that Sophos Central generated alert.
{"javaUUID":"111111aa-1a0a-11aa-a111-1111a1a01a11","source":"EndpointDevice-\\test","description":"Manual PUA cleanup required: 'PsKill' at 'C:\\test\\test\\Desktop\\testSuite.zip'","severity":"medium","when":"2024-05-17T08:27:35.081Z","data":{"core_remedy_items":{"totalItems":1,"items":[{"result":"FAILED_TO_DELETE","sophosPid":"","suspendResult":"NOT_APPLICABLE","processPath":"","descriptor":"C:\\test\\test\\Desktop\\testSuite.zip\\test.exe","type":"file"}]},"created_at":1715934458355,"endpoint_id":"111111aa-1a0a-11aa-a111-1111a1a01a11","endpoint_java_id":"111111aa-1a0a-11aa-a111-1111a1a01a11","endpoint_platform":"windows","endpoint_type":"computer","event_service_id":{"type":3,"data":"+t8G5vc+TxiW3IX3C/RrhQ=="},"inserted_at":1715934458355,"source_app_id":"TEST","source_info":{"ip":"10.0.0.1"},"threat_id":{"timestamp":1715934441,"date":1715934441000},"threat_status":"CLEANUP_FAILED","user_match_id":{"timestamp":1697208869,"date":1697208869000},"user_match_uuid":{"type":3,"data":"aaaaaaaa/aaaa111111"}},"type":"Event::Endpoint::CorePuaCleanFailed","location":"EndpointDevice-","id":"111111aa-1a0a-11aa-a111-1111a1a01a11","actionable":false,"customer_id":"111111aa-1a0a-11aa-a111-1111a1a01a11","created_at":"2024-05-17T08:27:38.371Z","threat":"PsKill","threat_cleanable":false,"event_service_event_id":"111111aa-1a0a-11aa-a111-1111a1a01a11"}
QRadar field name | Highlighted payload field name |
---|---|
Event ID | type |
Source IP | data. source_info.ip |
Device Time | created at |
Severity | severity |