Sophos schedul api read (SIEM). Credentials can be pass over SECRET-FILES. ...somenicedescription...
116
MVladislav
find source and docker-compose on github
defined to work with treafik
secrets:do not use TOKEN_INFO anymore instead use the 3 other secrets below
replace TOKEN_INFO with your token info
: 'API Access URL + Headers'
: 'API token setup steps: https://community.sophos.com/kb/en-us/125169'
: '<Copy API Access URL + Headers block from Sophos Central here>'
$echo "TOKEN_INFO" > config/secrets/token_info.txt
replace CLIENT_ID and CLIENT_SECRET with your token info
the variable TENANT_ID is optional if needed
: 'Client ID and Client Secret for Partners, Organizations and Tenants'
: '<Copy Client ID and Client Secret from Sophos Central here>'
$echo "CLIENT_ID" > config/secrets/client_id.txt
$echo "CLIENT_SECRET" > config/secrets/client_secret.txt
: 'Customer tenant Id'
$echo "TENANT_ID" > config/secrets/tenant_id.txt
.env credentialsget jwt:
<CLIENT_ID><CLIENT_SECRET>$curl -XPOST -H "Content-Type:application/x-www-form-urlencoded" \
-d "grant_type=client_credentials&client_id=<CLIENT_ID>&client_secret=<CLIENT_SECRET>&scope=token" \
https://id.sophos.com/api/v2/oauth2/token
get tenant-id:
<JWT>$curl -XGET -H "Authorization: Bearer <JWT>" https://api.central.sophos.com/whoami/v1
.env file following:NODE_ID=
NODE_ROLE=manager
NETWORK_MODE=overlay
BUILD_DATE=2022
PYTHON_VERSION=3.10.8-alpine3.16
GROUP=1000
USER=1000
VERSION=2022-10-17
# Host URL for Oauth token
AUTH_URL = https://id.sophos.com/api/v2/oauth2/token
# whoami API host url
API_HOST = api.central.sophos.com
# format can be json, cef, xlsx or keyvalue
FORMAT = json
SOPHOS_SIEM_HOME = /var/log/sophos
# filename can be syslog, stdout, any custom filename
FILENAME = result.txt
# if format set to xlsx
FILENAME_XLSX = result.xlsx
# endpoint can be event, alert or all
ENDPOINT = event
# syslog properties
# for remote address use <remoteServerIp>:<port>, for e.g. 192.1.2.3:514
# for linux local systems use /dev/log
# for MAC OSX use /var/run/syslog
# append_nul will append null at the end of log message if set to true
ADDRESS = /dev/log
FACILITY = daemon
SOCKTYPE = udp
APPEND_NUL = false
# cache file full or relative path (with a ".json" extension)
STATE_FILE_PATH = state/siem_sophos.json
# Delay the data collection by X minute to avoid events missing issue from Sophos API
# The issue could be due to some specific host being ahead in time for a few minute and Sophos Central would consider events received from that host as a checkpoint.
EVENTS_FROM_DATE_OFFSET_MINUTES = 0
# Delay the data collection by X minute.
ALERTS_FROM_DATE_OFFSET_MINUTES = 0
# Convert the dhost field to valid fqdn.
CONVERT_DHOST_FIELD_TO_VALID_FQDN = true
Content type
Image
Digest
sha256:5ee148524…
Size
288.7 MB
Last updated
almost 4 years ago
docker pull mvladislav/sophos:2022-10-17