Configure Sophos Central for Arctic Wolf monitoring using OAuth2
You can configure Sophos Central to send the necessary logs to Arctic Wolf® for security monitoring.
- If you have a Sophos Central API token to use for configuring monitoring, see Configure Sophos Central for Arctic Wolf monitoring using an API token.
- If you need to update your Sophos credentials and previously used an API token, contact your Concierge Security® Team (CST) to have the existing sensor deprecated before completing these steps.
These resources are required:
- Super Admin permissions for the Sophos Central environment that you want Arctic Wolf to monitor.
These actions are required:
- Install curl.
Note: If you are using Windows 10 or 11, curl is included. To verify that curl is installed, run
curl.exe -V. For more information, see curl.
Identify if Enterprise Management mode is enabled
If Enterprise Management mode is enabled for your Sophos Central account, then you must create credentials for each sub-estate that you want Arctic Wolf to monitor. Otherwise, you can create a single set of credentials for monitoring purposes.
Select a sub-estate
If Enterprise Management mode is enabled for your Sophos Central account, you must select the sub-estate that you want to create API token credentials for.
- Sign in to the Sophos Central portal.
- In the navigation menu, click Sub-Estates.
- Click the sub-estate that you want Arctic Wolf to monitor.
- Click Launch Sophos Central Admin to open the Sophos Central Admin console for that specific sub-estate.
Create Sophos Central credentials
Authenticate the API
Using cURL, you can make API calls to authenticate the API.
Find your tenant ID
Using cURL, you can find your tenant ID.
Provide Sophos Central credentials to Arctic Wolf
Time-based events are polled with a delay to make sure that data is available. For new deployments, Arctic Wolf begins polling and reviewing activity from approximately one hour prior to configuration success. If API credentials fail, for example due to expired credentials, Arctic Wolf notifies you and requests a new set of credentials. After receiving refreshed credentials, Arctic Wolf can only retrieve data from the previous 12 hours. Provide refreshed credentials within 12 hours of expiry to enable complete data polling and coverage.