Configure Sophos Central for Arctic Wolf monitoring using an API token

You can configure Sophos Central using an API token to send the necessary logs to Arctic Wolf® for security monitoring.

Note: This is a legacy method of configuring monitoring. If you are a new customer or want to use the updated OAuth2 method, see Configure Sophos Central for Arctic Wolf monitoring using OAuth2.

These resources are required:

  • Super Admin permissions for the Sophos Central environment that you want Arctic Wolf to monitor.

Identify if Enterprise Management mode is enabled

If Enterprise Management mode is enabled for your Sophos Central account, then you must create credentials for each sub-estate that you want Arctic Wolf to monitor. Otherwise, you can create a single set of credentials for monitoring purposes.

  1. Sign in to the Sophos Central portal.
  2. Review the navigation menu to see if the Sub-Estates tab:

Select a sub-estate

If Enterprise Management mode is enabled for your Sophos Central account, you must select the sub-estate that you want to create API token credentials for.

Note: You must repeat this process for each sub-estate that you want Arctic Wolf to monitor.
  1. Sign in to the Sophos Central portal.
  2. In the navigation menu, click Sub-Estates.
  3. Click the sub-estate that you want Arctic Wolf to monitor.
  4. Click Launch Sophos Central Admin to open the Sophos Central Admin console for that specific sub-estate.

Create Sophos Central API token credentials

  1. Sign in to the Sophos Central portal.
  2. In the navigation menu, click Global Settings.
  3. In the Administration section, click API Token Management.
  4. Click Add Token.
  5. In the Add Token dialog, in the Token Name field, enter a name fo the API token. For example, Arctic Wolf API Token.
  6. Click Save.

    The API Token Summary page appears.

  7. Copy each of these values and save them to a safe, encrypted location to provide to Arctic Wolf later:
    CAUTION: To prevent integration errors in the Arctic Wolf Unified Portal, you must use the Copy button to copy these values.
    • API Access URL
    • Headers — Copy this content into its own text file.

Provide Sophos Central credentials to Arctic Wolf

Note:

Time-based events are polled with a delay to make sure that data is available. For new deployments, Arctic Wolf begins polling and reviewing activity from approximately one hour prior to configuration success. If API credentials fail, for example due to expired credentials, Arctic Wolf notifies you and requests a new set of credentials. After receiving refreshed credentials, Arctic Wolf can only retrieve data from the previous 12 hours. Provide refreshed credentials within 12 hours of expiry to enable complete data polling and coverage.

  1. Sign in to the Arctic Wolf Unified Portal.
  2. In the navigation menu, click Data Collection > Cloud Sensors.
  3. Click Add Account +.
  4. On the Add Account page, click Sophos Central (Legacy Authentication).
  5. Configure these settings:
  6. Click Test and submit credentials.