Sophos Central sample event message

The following sample events are from the Sophos Central when you use the Sophos Central protocol.

Event - Endpoint

In the following sample event message, the event indicates the results of an action that returns the details of that Sophos Central generated event.

{"source":"n/a","when":"2024-04-23T16:22:10.159Z","severity":"low","type":"Event::Endpoint::UpdateRebootRequired","location":"AA1AAAA-1234AAA1","id":"111111aa-1a0a-11aa-a111-1111a1a01a11","group":"UPDATING","endpoint_id":"111111aa-1a0a-11aa-a111-1111aaaaaaa","endpoint_type":"server","customer_id":"111111aa-1a0a-11aa-a111-1111a1a01a11","created_at":"2024-04-23T16:22:10.170Z","source_info":{"ip":"10.0.0.1"},"name":"Reboot to complete update; computer stays protected in the meantime"}
Table 1. Highlighted values in the Sophos Central - Event
QRadar field name Highlighted payload field name
Event ID type
Source IP source_info.ip
Device Time created at
Severity severity

Alert - Endpoint

In the following sample event message, the event indicates the results of an action that returns the details of that Sophos Central generated alert.

{"javaUUID":"111111aa-1a0a-11aa-a111-1111a1a01a11","source":"EndpointDevice-\\test","description":"Manual PUA cleanup required: 'PsKill' at 'C:\\test\\test\\Desktop\\testSuite.zip'","severity":"medium","when":"2024-05-17T08:27:35.081Z","data":{"core_remedy_items":{"totalItems":1,"items":[{"result":"FAILED_TO_DELETE","sophosPid":"","suspendResult":"NOT_APPLICABLE","processPath":"","descriptor":"C:\\test\\test\\Desktop\\testSuite.zip\\test.exe","type":"file"}]},"created_at":1715934458355,"endpoint_id":"111111aa-1a0a-11aa-a111-1111a1a01a11","endpoint_java_id":"111111aa-1a0a-11aa-a111-1111a1a01a11","endpoint_platform":"windows","endpoint_type":"computer","event_service_id":{"type":3,"data":"+t8G5vc+TxiW3IX3C/RrhQ=="},"inserted_at":1715934458355,"source_app_id":"TEST","source_info":{"ip":"10.0.0.1"},"threat_id":{"timestamp":1715934441,"date":1715934441000},"threat_status":"CLEANUP_FAILED","user_match_id":{"timestamp":1697208869,"date":1697208869000},"user_match_uuid":{"type":3,"data":"aaaaaaaa/aaaa111111"}},"type":"Event::Endpoint::CorePuaCleanFailed","location":"EndpointDevice-","id":"111111aa-1a0a-11aa-a111-1111a1a01a11","actionable":false,"customer_id":"111111aa-1a0a-11aa-a111-1111a1a01a11","created_at":"2024-05-17T08:27:38.371Z","threat":"PsKill","threat_cleanable":false,"event_service_event_id":"111111aa-1a0a-11aa-a111-1111a1a01a11"}
Table 2. Highlighted values in the Sophos Central - Alert
QRadar field name Highlighted payload field name
Event ID type
Source IP data. source_info.ip
Device Time created at
Severity severity