This quick start guide will help Accenture MDR customers configure Sophos Central Cloud to allow log collection from the Log Collection Platform (LCP).
The document includes the following topics:
Table of Contents | ||||
---|---|---|---|---|
|
Supported Versions
A list of supported versions is available in the Accenture MDR Supported Products List document (Accenture_MDR_Supported_Products_List.xlsx) which can be found in
Accenture MDR Portal - https://mss.accenture.com/PortalNextGen/Reports/Documents
Port Requirements
Table1-1: Port requirements for LCP communication.
Source | Destination | Port | Description |
LCP | Sophos Central Cloud | 443 (TCP) | Default port |
Configuring Sophos Central Cloud
Log in to the Sophos Central Admin.
2. Navigate to Global settings > API Token Management.
3. Click on Add token from the top right corner of the screen to create a new token.
4. Select a token name and click on the Save button. The API Token Summary for this token will be displayed as follows.
5. Click on Copy to copy your API Access URL and Headers from the API Token Summary section to SIEM.
LCP Configuration parameters
Table 1-2: The Sophos Central Cloud event collector(API-3869) properties to be configured by MDR are shown in the table.
Property | Default Value | Description |
Sophos Central Cloud URL | Custom Value | Sophos Central Cloud URL mentioned in the Pre-Installation Questionnaire (PIQ). Example - https://api1.central.sophos.com/gateway |
API Key | Custom value | Unique API key for the token generated by the customer |
Authorization | Custom value | Type of API authorization |
Client Secret Key | Custom value | Authentication key for retrieving logs |