---
title: "Integrate with Sophos"
canonical: "https://docs.aryaka.com/space/KNOW/893354044/Integrate%20with%20Sophos"
format: markdown
---
Aryaka and Sophos can be integrated such that your logs are sent from Aryaka to Sophos for analysis. To integrate Aryaka with Sophos, you must complete the following configuration steps: Configure the integration in Sophos Central.  This allows Sophos to receive your logs from Aryaka. Configure the integration in MyAyaka.  This allows Aryaka to send your logs to Sophos.  These configurations are described in the following sections.  Configure the integration in Sophos Central  Within Sophos Central, you must configure an appliance, which receives data from Aryaka using syslog exports and forwards it to Sophos for analysis. This configuration requires you to create an image of the appliance, download it, and deploy it to a virtual machine (VM). After you’ve completed the  Configure the integration in MyAryaka  procedure, this appliance is able to receive data from Aryaka. You must have a Network integrations license pack with Sophos to use this feature. To integrate Aryaka with Sophos In Sophos Central, navigate to  Threat Analysis Center  >  Integrations  >  Marketplace  and click  Aryaka . The Aryaka page opens, which allows you to add integrations and view existing integrations.  Click  Add Configuration  in Data Ingest (Security Alerts). The integration setup steps appear. Note that if this is the first integration you’ve added, you are asked for details about your internal domains and IPs.  You can choose to use an existing appliance, but the following assumes you are configuring a new appliance. Enter a name and a description for the integration, then click  Create new appliance . Enter a name and a description for the appliance, then select a virtual platform (currently VMware ESXi 6.7 Update 3 or later and Microsoft Hyper-V 6.0.6001.18016 (Windows Server 2016) or later are supported). Specify the IP settings for the internet-facing network ports. This sets up the management interface for the appliance. Select  DHCP  to assign the IP address automatically. Note that if you select DHCP, you must reserve the IP address. Select  Manual  to specify network settings. Select the Syslog IP version, then enter the Syslog IP address.  This IP address is required when configuring the integration in MyAryaka. The Protocol is set to TCP by default—this cannot be changed. Click  Save . The integration is created and it appears in your list of integrations.  In the integration details, you can see the port number for the appliance. This is required when configuring the integration in MyAryaka. When the appliance image is ready, download the image for you platform from the list of integrations. For example, if using ESXi, click  Download OVA . When the image download finishes, deploy it on your VM.  Configure the integration in MyAryaka You must configure a SIEM integration to send your logs from Aryaka to Sophos. For additional details on SIEM integration in MyAryaka, see the  Configure SIEM integration  topic.  Currently, you can achieve the best insights from this integration if you have  Aryaka SmartSecure IPS  and you export IPS event logs to Sophos (as described in the following procedure). To export log content to Sophos If it is not already open, navigate to the SIEM page: Log into MyAryaka. The Home page appears. Click  Global Settings  in the left navigation pane. The Global Settings page appears and displays a series of tiles. Click  Manage  in the SIEM tile. The SIEM page appears. Click  Add SIEM Configuration . The Add SIEM Configuration page appears with the Status field set to Draft (New). Configure the following fields in the SIEM Details pane: Enter a name and description of this connection in the corresponding fields. Currently, the Vendor functionality defaults to Generic and cannot be edited. Configure the following fields in the Connectivity Details pane: Click the  SIEM Log Transport Method  drop-down list and select  Network Port .  In the SIEM Endpoint IP or Domain Name field, enter the syslog IP address that you configured during the  Configure the integration in Sophos Central  procedure. Click the  Protocol  drop-down list and select  TCP . In the Port Number field, enter the listening port for this connection that you configured during the  Configure the integration in Sophos Central  procedure. In the Log Types pane, select the types of logs you want sent to Sophos: Security Logs—Send logs from your Aryaka SmartSecure NGFW-SWG service. Logs include insights from SASE and Non-SASE security engines. IPS Event Logs—Send logs from your Aryaka SmartSecure IPS service.  Note:  this toggle is only displayed if you have the Aryaka SmartSecure IPS add-on service. Flow Logs—Send logs from your SD-WAN service. Logs contain basic connection details and traffic statistics. These logs do not contain any security engine related details. Private Access Logs—Send logs from your Private Access service.  Note:  this toggle is only displayed if you have at least one Private Access region enabled. Click  Submit . A message warns that you cannot edit the SIEM configuration until after Aryaka Support completes the configuration. Click  OK . A message confirms the request was submitted and the Status field is set to Provisioning. When the change request is complete, the SIEM page (at Config > Security > SIEM) displays a tile with the SIEM name, the vendor type (Generic), and the status of Configured. In this topic Related topics SIEM Configure SIEM integration Security log attributes for SIEM integration