---
title: Sophos Central Integration
description: AgileBlue can collect Alert and Event logs from Sophos Central by leveraging the SIEM Integration API. Customers can also elect to leverage Sophos for host isolation via the AgileBlue SecOps Platform.
---

[Skip to content](https://help.agileblue.com/sophos-central-integration#main-content)

English

Show submenu for translations

[Contact AgileBlue Support](https://help.agileblue.com/kb-tickets/new?hsLang=en) [Customer portal](https://help.agileblue.com/support-ticket-status?hsLang=en)

![FullColor-800px-Aug-04-2025-07-56-16-5066-PM.png\]](https://help.agileblue.com/hs-fs/hubfs/FullColor-800px-Aug-04-2025-07-56-16-5066-PM.png?height=32&name=FullColor-800px-Aug-04-2025-07-56-16-5066-PM.png)

Open main navigation

Close main navigation

- English
  
  Show submenu for translations
- [Contact AgileBlue Support](https://help.agileblue.com/kb-tickets/new)
- [Customer portal](https://help.agileblue.com/support-ticket-status)
- AgileBlue Portal

 AgileBlue Portal

 Hello. How can we help you?

- There are no suggestions because the search field is empty.

1. [Help Center](https://help.agileblue.com/?hsLang=en)
2. [Application Integrations](https://help.agileblue.com/application-integrations?hsLang=en)
3. [Third-Party EDR](https://help.agileblue.com/application-integrations?hsLang=en#third-party-edr)

# Sophos Central Integration

## AgileBlue can collect Alert and Event logs from Sophos Central by leveraging the SIEM Integration API. Customers can also elect to leverage Sophos for host isolation via the AgileBlue SecOps Platform.

### Supported Platform Version

- Sophos Central SIEM Integration API version v1

---

### Monitoring Integration

*Note: A user with Super Admin access will need to complete the setup process for this integration.*

1. Sign in to [Sophos Central](https://central.sophos.com/manage/) and navigate to **My Products \> General Settings \> API Credentials Management**
2. Select **Add Credential**
3. Provide a name of your choosing under **Credential name** (the description section is optional)
4. Assign the role of **Service Principal ReadOnly**
5. Click **Add**
6. On the **API credential summary** page, copy your **Client ID **to a secure location
7. Click **Show Client Secret** and copy this value to a secure location as well
8. Follow sections 2 and 3 in this Sophos guide to collect your Tenant ID and Request URL
9. Securely send the following values back to AgileBlue Support: 
     1. Client ID
     2. Client Secret
     3. Tenant ID
     4. Request URL (Ex. https://api-{dataRegion}.central.sophos.com)
     5. API credential expiration date

---

### Host Isolation Integration

In order to select Sophos as the default Host Isolation engine within the AgileBlue platform, follow the steps below to create a second API connection and enable the integration within our portal.

1. Sign in to [Sophos Central](https://central.sophos.com/manage/) and navigate to **My Products \> General Settings \> API Credentials Management**
2. Select **Add Credential**
3. Provide a name of your choosing under **Credential name** (the description section is optional)
4. Assign the role of **Service Principal Super Admin**
5. Click **Add**
6. On the **API credential summary** page, copy your **Client ID **to a secure location
7. Click **Show Client Secret** and copy this value to a secure location as well
8. Next, navigate to the [AgileBlue Portal](https://portal.agileblue.com/login) and log in
9. Select **Settings** then **Alert Playbook**
10. Scroll to the **Host Isolation System** section and select **Sophos **from the dropdown menu
11. Enter the **Client ID** and **Client Secret** gathered in steps 6 and 7

---

### **Need Help?**

AgileBlue is always here to support you and ensure you are 100% successful. If there are any issues with the installation or if you have any questions, please reach out to [**AgileBlue Support**](https://help.agileblue.com/kb-tickets/new?hsLang=en).

*Email: support@agileblue.com   
Phone: (216) 606-9400🚨*

- [Agent Installation](https://help.agileblue.com/agent-installation?hsLang=en#main-content)

    - [Windows](https://help.agileblue.com/agent-installation?hsLang=en#windows)
    - [Mac](https://help.agileblue.com/agent-installation?hsLang=en#mac)
    - [Linux](https://help.agileblue.com/agent-installation?hsLang=en#linux)
    - [Syslog Collection](https://help.agileblue.com/agent-installation?hsLang=en#syslog-collection)
    - [Agent Management](https://help.agileblue.com/agent-installation?hsLang=en#agent-management)
- [Application Integrations](https://help.agileblue.com/application-integrations?hsLang=en#main-content)

    - [Microsoft Tools](https://help.agileblue.com/application-integrations?hsLang=en#microsoft-tools)
    - [Third-Party EDR](https://help.agileblue.com/application-integrations?hsLang=en#third-party-edr)
    - [Other Security Tools](https://help.agileblue.com/application-integrations?hsLang=en#other-security-tools)
- [Cloud Integrations](https://help.agileblue.com/cloud-integrations?hsLang=en)
- [AgileBlue Features](https://help.agileblue.com/agileblue-features?hsLang=en#main-content)

    - [Portal Management](https://help.agileblue.com/agileblue-features?hsLang=en#portal-management)
    - [Support Systems](https://help.agileblue.com/agileblue-features?hsLang=en#support-systems)
- [Vulnerability Scanning](https://help.agileblue.com/vulnerability-scanning?hsLang=en)
- [Release Notes](https://help.agileblue.com/release-notes?hsLang=en)

[![AgileBlue](https://help.agileblue.com/hs-fs/hubfs/Current-Website-Logo-Replacement.png?width=1321&height=648&name=Current-Website-Logo-Replacement.png "AgileBlue")](http://www.agileblue.com)

AgileBlue Support Phone: 216.606.9400

Copyright © 2026, AgileBlue