Sophos Intercept X
Connect Sophos Intercept X to Radiant Security to ingest endpoint alerts from Sophos Central for AI triage.
Last updated
Was this helpful?
Connect Sophos Intercept X to Radiant Security to ingest endpoint alerts from Sophos Central for AI triage.
Create API credentials in Sophos Central and use them to connect Sophos Intercept X (Sophos Endpoint) to Radiant Security. Once connected, Radiant ingests Sophos endpoint alerts and runs them through the AI triage pipeline.
At the end of this configuration, you will provide Radiant Security with the following values:
Client ID
Client Secret
Log in to your Sophos Central Admin account as an Enterprise Super Admin.
Log in to Radiant Security.
From the navigation menu, select Settings > Data Connector and click + Add Connector.
Search for and select the Sophos API data feed option, then click Data Feeds.
Under Select your data feeds, select Sophos Intercept X and click Credentials.
Under Credential Name, give the credential an identifiable name (e.g., Sophos Forensics).
Under Required Credentials, paste the Client ID and Client Secret values copied from Sophos Central.
Click Add Connector.
After Sophos Intercept X begins forwarding, confirm alerts and events are reaching Radiant.
In Radiant, navigate to Log Management.
Filter by rs_connectorType:"sophos_intercept_x".
Confirm recent alerts and events appear.
Allow several minutes for alerts and events to be parsed, indexed, and available for search.
Last updated
Was this helpful?
Was this helpful?