Sophos MDR integration
The Sophos Managed Detection and Response (MDR) integration sends alerts to the Sophos MDR service.
Sophos MDR is a fully-managed, 24/7 threat hunting, detection, and remediation service.
Sophos Cloud Optix uses the MDR integration to send supported alerts and events to Sophos MDR.
Licensing changes
The Sophos Managed Threat Response (MTR) service changed to Managed Detection and Response (MDR) in November 2022.
MTR Advanced licenses
For customers who had an MTR Advanced license, Sophos Cloud Optix continues to integrate with the Sophos managed service. It sends anomaly detection alerts and Amazon GuardDuty events to Sophos MDR.
This happens automatically, there are no setup steps.
Sophos MDR and MDR Complete licenses
Customers with new Sophos MDR and MDR Complete licenses must set up the Sophos Cloud Optix integration in Sophos Central.
To do this, do as follows:
- Sign in to Sophos Central.
- Click Threat Analysis Center > Integrations.
- Click the Sophos Cloud Optix card and follow the instructions.
The MDR service now receives anomaly detection alerts from Cloud Optix.
Monitoring
You can see the status of the Sophos Cloud Optix MDR integration in Sophos Central.
How you do this depends on whether you had an MTR Advanced license, or you have a new Sophos MDR or MDR Complete license.
MTR Advanced licenses
If you had an MTR Advanced license, to monitor the status of your connection do as follows.
- Sign in to Sophos Central.
- Click MDR to open the MDR dashboard.
- Look for Connector status report.
See the Connector status report section of MDR dashboard.
Sophos MDR and MDR Complete licenses
If you have a Sophos MDR or MDR Complete license, to monitor the status of your connection do as follows.
- Sign in to Sophos Central.
- Sign in to Sophos Central.
- Go to Threat Analysis Center > Integrations.
- Click Sophos Cloud Optix.
- Integration Status shows you whether the integration is active or not.
See Sophos Cloud Optix.