Sophos Central SIEM CEF Events
Sophos Central endpoint events in the CEF that the Sophos Central SIEM Integration script (siem.py 2.1.0) writes from the SIEM API events endpoint, as ECS JSON with the CEF line in event.original. About 640 events a day from 74 endpoints, mostly update checks, web control blocks, peripheral alerts and scheduled scans, with a normal malware and PUA baseline concentrated on three busy endpoints. Recurring episodes show malware on one endpoint that survives a failed cleanup, is detected again and is then cleaned up.
Quick Start
uv tool install eventum-generator
git clone https://github.com/eventum-generator/content-packs.git
cd content-packs
eventum generate \
--path generators/security-sophos-central/generator.yml \
--id sophos-central \
--live-mode trueEvent Types
| Event ID | Description | Frequency | Category |
|---|---|---|---|
| Event::Endpoint::UpdateSuccess | Update succeeded | 68.8% of records | host |
| Event::Endpoint::WebControlViolation | Website blocked by web control | 17.8% of records | web |
| Event::Endpoint::Device::AlertedOnly | Peripheral allowed (device control in alert-only mode) | 6.0% of records | host |
| Event::Endpoint::SavScanComplete | Scheduled scan completed | 3.9% of records | host |
| Event::Endpoint::Threat::Detected | Malware detected | 1.1% of records | malware |
| Event::Endpoint::Threat::CleanedUp | Malware cleaned up | 0.8% of records | malware |
| Event::Endpoint::UpdateFailure | Update failed | 0.7% of records | host |
| Event::Endpoint::UserAutoCreated | New user added automatically | 0.4% of records | iam |
| Event::Endpoint::Threat::CleanupFailed | Manual cleanup required | 0.2% of records | malware |
| Event::Endpoint::Threat::PuaDetected | PUA detected | 0.2% of records | malware |
| Event::Endpoint::Threat::PuaCleanupFailed | Manual PUA cleanup required | 0.1% of records | malware |
Realism Features
- 74 endpoints (64 workstations with one user each, 10 servers) report independently, about 640 events a day. Workstations (about 545 a day) follow the office day in UTC: about 10 events an hour from 20:00 to 05:00, rising through 05:00-07:00 to about 35 an hour from 07:00 to 17:00 and falling back by 20:00; servers (about 95 a day) send about 4 an hour around the clock. Each day differs from the base volume by up to 3%, weekends carry the same volume as weekdays, and there is no holiday cycle. Rate and shares are scenario assumptions, not Sophos measurements.
- Most records are routine: every endpoint checks for updates several times a day and about 1% of the checks fail, and each endpoint completes a scheduled scan about twice a week. Workstation users hit blocked web categories (games, streaming, social networking, gambling and others; about 110 blocks a day) and connect USB drives and phones that device control allows with an alert (about 37 a day), almost entirely in the office day; a new user is added automatically two or three times a day.
- Threat activity is a normal baseline rather than an outbreak: about 5 malware detections, fewer than one PUA detection and about one failed cleanup a day, most on two workstations whose users download a lot and one terminal server; in a typical week about 9-17 endpoints have a detection and 3-7 a failed cleanup. Mal/Generic-S and ML/PE-A make up about 60% of the malware detections. Incidents are automatic cleanups 30 s to 6 min after detection (median about 2 min), repeat detections of the same file 4-36 min apart, failed cleanups resolved manually after a median of about 1.5 hours or followed by another detection, and PUA detections often followed by a failed PUA cleanup.
- Episodes keep the total volume and its hour curve, replacing about four routine records each; threat records are not reduced, so at the default interval the tenant has about two more detections and one more failed cleanup a day than with anomaly_mode false. Episode file paths come from the same folders and file names as ordinary detections. An ordinary cleanup that would complete the ordered sequence for the same endpoint, threat and file within two hours of the first detection is reported as CleanupFailed at the same time, as is any later cleanup of that file inside the same window; this affects less than one ordinary cleanup a month.
- The CEF follows siem.py 2.1.0 and name_mapping.py: threat descriptions are split into detection_identity_name and filePath, severity is mapped low 1, medium 5, high 8, source_info.ip is flattened, the renamed fields move to the end of the extension, and = and backslash in values are escaped with a backslash. end is when the endpoint reported the event and rt when Central recorded it, seconds or occasionally tens of minutes later. Records a real endpoint sends seconds apart (a detection and its cleanup or failed cleanup) are one to several minutes apart here, at night up to about half an hour.
- Only SIEM API event schema fields are used, plus the datastream field the script adds; the API key order follows the Elastic sophos_central test fixture. Web control and peripheral texts follow published SIEM samples, and the PUA cleanup text follows the script changelog; the other descriptions, per-type severities and some groups are modeled, and no live-tenant raw CEF line was found, so byte parity is established only against the script code.
- Events endpoint only: no alerts records, IPS, AMSI, core detection, web filtering, application control, compliance or DLP events. Names, RFC 1918 addresses, .example web domains and identifiers are synthetic; the shipped output writes ECS JSON documents rather than the script stdout, file or syslog transport.
Sample Output
{
"@timestamp": "2026-09-02T20:12:30.847Z",
"ecs": {
"version": "8.11.0"
},
"event": {
"kind": "event",
"dataset": "sophos_central.event",
"module": "sophos_central",
"category": [
"malware"
],
"type": [
"info"
],
"code": "Event::Endpoint::Threat::Detected",
"action": "Malware detected: 'ML/PE-A' at 'C:\\Users\\yuri.smith\\Desktop\\crack_keygen.exe'",
"id": "42559af0-b52a-4079-b3eb-60c7479a04ad",
"created": "2026-09-02T20:12:35.761Z",
"severity": 8,
"original": "CEF:0|sophos|sophos central|1.0|Event::Endpoint::Threat::Detected|ML/PE-A|8|source_info_ip=10.20.15.139 customer_id=6f1c2a9e-3b7d-4c58-9e21-0d4b8a7f5c13 threat=ML/PE-A endpoint_id=595864a4-07e6-42be-8e14-f2deb6c1b27d endpoint_type=computer group=MALWARE id=42559af0-b52a-4079-b3eb-60c7479a04ad datastream=event detection_identity_name=ML/PE-A filePath=C:\\\\Users\\\\yuri.smith\\\\Desktop\\\\crack_keygen.exe suser=CONTOSO\\\\yuri.smith rt=2026-09-02T20:12:35.761Z duid=4cc74ae9af9f2e66038ff7e7 end=2026-09-02T20:12:30.847Z dhost=WS-ENG-679"
},
"observer": {
"vendor": "Sophos",
"product": "Sophos Central"
},
"organization": {
"id": "6f1c2a9e-3b7d-4c58-9e21-0d4b8a7f5c13"
},
"host": {
"name": "WS-ENG-679",
"id": "595864a4-07e6-42be-8e14-f2deb6c1b27d"
},
"source": {
"ip": "10.20.15.139"
},
"related": {
"ip": [
"10.20.15.139"
],
"hosts": [
"WS-ENG-679"
],
"user": [
"yuri.smith"
]
},
"sophos_central": {
"event": {
"type": "Event::Endpoint::Threat::Detected",
"group": "MALWARE",
"severity": "high",
"source": "CONTOSO\\yuri.smith",
"location": "WS-ENG-679",
"when": "2026-09-02T20:12:30.847Z",
"created_at": "2026-09-02T20:12:35.761Z",
"endpoint": {
"id": "595864a4-07e6-42be-8e14-f2deb6c1b27d",
"type": "computer"
},
"datastream": "event",
"user_id": "4cc74ae9af9f2e66038ff7e7",
"threat": "ML/PE-A",
"detection_identity_name": "ML/PE-A"
}
},
"user": {
"name": "yuri.smith",
"domain": "CONTOSO",
"id": "4cc74ae9af9f2e66038ff7e7"
},
"file": {
"path": "C:\\Users\\yuri.smith\\Desktop\\crack_keygen.exe",
"name": "crack_keygen.exe"
}
}Parameters
| Parameter | Default | Description |
|---|---|---|
| anomaly_mode | true | Add the recurring Detected, CleanupFailed, Detected, CleanedUp episode; false produces background only |
| anomaly_interval_hours | 24 | Hours from the start of one episode to the time the next is due, 3 to 8,760 |
| customer_id | 6f1c2a9e-3b7d-4c58-9e21-0d4b8a7f5c13 | Sophos Central tenant (customer) ID in customer_id |
| domain | CONTOSO | Windows domain in suser (DOMAIN\user) for workstation users |
Related Generators
Suricata IDS/IPS
Suricata EVE JSON output — IDS alerts with ET Open signatures, DNS/HTTP/TLS/SSH protocol logs, NetFlow records, and anomaly detections with correlated flow IDs and MITRE ATT&CK mapping.
Palo Alto Threat
Palo Alto PAN-OS Threat logs — IPS vulnerability exploits, antivirus detections, anti-spyware (DNS sinkhole and C2 callback), WildFire cloud verdicts, file type matching, and network scan detection with correlated severity, action, and threat category fields.
Palo Alto URL Filtering
Palo Alto PAN-OS URL Filtering logs — web browsing activity with 65+ URL categories, allow/block/continue/override actions, App-ID application attribution, and content type inspection.