.png)
Sophos Central Integration Guide
Connect Sophos Central REST APIs, event feeds, and selected webhook notifications with enterprise workflows, SIEMs, ITSM platforms, and reporting systems.
Sophos Central integration options at a glance
Sophos Central primarily integrates through REST APIs covering endpoints, alerts, events, policies, tenants, and other product-specific services. Its event and SIEM-oriented APIs support scheduled or incremental retrieval, while webhook-style notifications are available for selected alert and notification scenarios rather than every event type. OAuth 2.0 client-credentials authentication uses a client ID, client secret, bearer tokens, API permissions, and tenant-aware access. Martini can consume these APIs, manage pagination and checkpoints, normalize JSON responses, receive supported webhook requests, apply routing rules, and forward data to SIEM, ITSM, CMDB, reporting, or notification platforms.
| Integration point | Supported by Sophos Central? | Common use cases | How Martini supports it |
|---|---|---|---|
| REST APIs | Yes | Manage and retrieve endpoints, alerts, events, policies, tenants, and product-specific Sophos Central resources. | Martini can consume the documented REST APIs, authenticate requests, paginate responses, transform JSON, and orchestrate downstream writes. |
| Webhooks / outbound callbacks | Limited | Receive selected alert or notification scenarios with lower latency than scheduled polling. | Martini can expose an API endpoint or start-trigger workflow, validate requests, normalize payloads, and route them to downstream systems. |
| Event and SIEM access | Yes | Retrieve security and administrative events for SIEM forwarding, monitoring, investigation, and audit-oriented synchronization. | Martini can poll incrementally, persist timestamps or cursors, map events to a common schema, and update checkpoints after successful delivery. |
| Bulk / async / batch APIs | Limited | Process paginated list responses and event-oriented batches where supported by the relevant API family. | Martini can implement bounded pagination, scheduled batches, checkpointing, and controlled execution limits; a universal bulk API was not confirmed. |
| Authentication | Yes | Authenticate API requests with OAuth 2.0 client credentials, bearer tokens, application permissions, and tenant identification. | Martini can keep client secrets in secure configuration, request tokens, renew expired tokens, and apply tenant-aware request handling. |
| GraphQL APIs | Not confirmed | No official Sophos Central GraphQL API was confirmed in the reviewed material. | Martini should use the documented REST, event, and supported webhook mechanisms instead. |
| SOAP APIs | Not confirmed | No official Sophos Central SOAP API was confirmed in the reviewed material. | Martini should use the documented REST, event, and supported webhook mechanisms instead. |
| File / attachment APIs | Not confirmed | Sophos Central is not primarily a file-management platform; a general-purpose attachment API was not confirmed. | Martini can process files when another confirmed endpoint supplies them, but should not assume arbitrary Sophos Central attachment access. |
How Sophos Central exposes data and business events
Sophos Central REST APIs
REST is Sophos Central’s primary programmatic integration model. Product-specific APIs expose resources such as endpoints, alerts, events, policies, tenants, and other services, with JSON responses and HTTP status codes used for request and error handling.
Martini implementation pattern
Martini implementation pattern: a workflow authenticates with OAuth 2.0 client credentials, calls the applicable REST resource, handles pagination and API responses, transforms the result, applies business rules, and writes to one or more target systems.
Implementation sequence
Sophos Central Events and SIEM Access
Sophos Central provides event and SIEM-oriented access for retrieving security and administrative events. This mechanism is generally better suited to scheduled or incremental polling than assuming every event is delivered as a real-time callback.
Martini implementation pattern
Martini implementation pattern: a scheduled workflow reads the last successful timestamp, cursor, or event identifier, retrieves new events, normalizes them for a SIEM or data store, delivers them, and commits the checkpoint only after downstream processing succeeds.
Implementation sequence
Sophos Central Webhook Notifications
Sophos Central supports webhook-style integrations for selected alert or notification scenarios. Coverage, payloads, retry behavior, and configuration depend on the selected integration and should not be treated as universal across all Sophos Central events.
Martini implementation pattern
Martini implementation pattern: expose a protected Martini API or start-trigger workflow, validate the incoming request, normalize the notification, apply severity and tenant routing, and use an idempotency key before writing to downstream systems.
Implementation sequence
Common Sophos Central integration patterns
Pattern 1: Route Sophos Central alerts to ServiceNow
When to use this pattern
Use this pattern when security operations need incidents and tasks created from selected Sophos Central alerts. Webhooks can reduce latency where the required alert category is supported, while polling provides reconciliation and replay options.
Integration direction
Example Mapping
| Sophos Central Field | Canonical Field | Target Field |
|---|---|---|
| alert.id | sourceAlertId | u_sophos_alert_id |
| severity | priority | priority |
| description | summary | short_description |
| tenant.id | tenantId | u_sophos_tenant_id |
Martini implementation pattern
Martini receives supported notifications or polls Alerts, classifies records by severity, product, tenant, and endpoint, enriches the incident with normalized context, and creates or updates ServiceNow records. It stores the source identifier and retries transient failures without creating duplicates.
Martini capabilities used
- workflows
- API consumption
- data mapping
- business rules
- error handling
- scheduled execution
Pattern 2: Forward Sophos Central events to a SIEM
When to use this pattern
Use this pattern when security teams need centralized search, correlation, dashboards, and detection rules for Sophos Central event data. Incremental polling is appropriate when complete or auditable event collection matters more than callback latency.
Integration direction
Example Mapping
| Sophos Central Field | Canonical Field | Target Field |
|---|---|---|
| event.id | eventId | event_id |
| event.createdAt | eventTime | time |
| event.type | eventType | event_type |
| tenant.id | tenantId | sophos_tenant_id |
Martini implementation pattern
A scheduled Martini workflow loads a tenant-scoped checkpoint, retrieves new events, maps product-specific fields into the selected SIEM format, and forwards the batch. The workflow advances the checkpoint only after successful delivery and applies bounded backoff for rate limits or transient errors.
Martini capabilities used
- scheduled workflows
- API consumption
- checkpoint management
- data transformation
- retry handling
- monitoring
Pattern 3: Synchronize Sophos Central endpoints with a CMDB
When to use this pattern
Use this pattern to maintain an operational inventory of protected computers and servers. Scheduled reconciliation helps identify health changes, group changes, deactivated endpoints, and objects that are no longer visible within the authorized tenant scope.
Integration direction
Example Mapping
| Sophos Central Field | Canonical Field | Target Field |
|---|---|---|
| endpoint.id | sourceEndpointId | correlation_id |
| hostname | hostName | name |
| health.status | healthStatus | u_protection_status |
| group.id | endpointGroupId | u_sophos_group_id |
Martini implementation pattern
Martini pages through the Endpoint API, maps endpoint identity and protection details, applies tenant and retirement rules, and upserts CMDB records. A controlled reconciliation step handles missing or deactivated endpoints without treating temporary API visibility issues as deletion.
Martini capabilities used
- scheduler triggers
- pagination
- mapping
- reconciliation logic
- business rules
- database or API writes
Pattern 4: Produce multi-tenant Sophos Central policy reports
When to use this pattern
Use this pattern for partner or managed-security reporting across authorized Sophos Central customer environments. The workflow should preserve tenant boundaries and report only objects available to the application's permissions and subscriptions.
Integration direction
Example Mapping
| Sophos Central Field | Canonical Field | Target Field |
|---|---|---|
| tenant.id | tenantId | tenant_id |
| policy.id | policyId | policy_id |
| policy.name | policyName | policy_name |
| policy.updatedAt | lastUpdated | updated_at |
Martini implementation pattern
Martini iterates through authorized tenants, retrieves policy, alert, endpoint, and tenant information, normalizes product-specific fields, and writes reporting tables. Validation, tenant-aware error handling, and run-level audit data make partial failures visible without mixing customer data.
Martini capabilities used
- workflow orchestration
- REST API consumption
- multi-tenant routing
- data mapping
- SQL persistence
- error handling
Applications commonly integrated with Sophos Central
Sophos Central data can be routed to security operations, IT service management, notification, identity, and reporting applications. The exact integration scope depends on Sophos Central API permissions, tenant model, product subscription, and the target application's ingestion interface.
| Application | Scenario | Direction | Martini Pattern |
|---|---|---|---|
| ServiceNow | Create and update security incidents, operational tasks, and configuration records from Sophos Central alerts and endpoint data. | Sophos Central → Martini → ServiceNow | Martini can receive selected webhook notifications or poll the Alerts API, classify alerts by severity and tenant, map them to ServiceNow incident or configuration models, and use identifiers to avoid duplicate records. |
| Splunk | Centralize Sophos Central events and alerts for search, correlation, dashboards, and detection rules. | Sophos Central → Martini → Splunk | A scheduled Martini workflow retrieves incremental event data, converts it to the agreed Splunk ingestion format, records a successful checkpoint, and retries transient delivery failures. |
| Microsoft Sentinel | Send Sophos Central security events to Microsoft’s cloud SIEM for correlation with identity, endpoint, and cloud telemetry. | Sophos Central → Martini → Microsoft Sentinel | Martini polls the applicable event or SIEM API, normalizes event fields, applies tenant and severity routing, and forwards accepted events through the selected Sentinel ingestion interface. |
| Jira | Create investigation or remediation issues from actionable Sophos Central alerts. | Sophos Central → Martini → Jira | Martini filters alert types and severity, maps alert context to Jira issue fields, stores the Sophos identifier for idempotency, and optionally processes issue status updates. |
| Microsoft Teams | Notify security or IT operations channels about selected high-severity Sophos Central alerts. | Sophos Central → Martini → Microsoft Teams | A webhook-triggered or polling workflow evaluates alert severity and product, formats a concise notification, and sends only approved events to the relevant Teams destination. |
| Slack | Deliver selected alert notifications to security channels and support triage workflows. | Sophos Central → Martini → Slack | Martini receives or retrieves Sophos Central alerts, applies channel-routing rules, transforms the payload into the target message structure, and records delivery outcomes. |
| Okta | Correlate Sophos Central endpoint or user-related security signals with identity events and access workflows. | Sophos Central → Martini → Okta | Martini maps approved Sophos Central security signals to Okta-related workflows while applying explicit authorization, tenant, and action rules; reverse actions require validation against both platforms. |
| NetSuite | Provide security or operational reporting alongside business-system governance data in organizations using NetSuite. | Sophos Central → Martini → NetSuite | Martini periodically normalizes authorized tenant, alert, endpoint, or policy information and sends selected reporting data to NetSuite or an associated reporting layer. |
How to build a Sophos Central integration in Martini
Objective
Configure OAuth 2.0 client-credentials access and tenant-aware request handling without embedding credentials or long-lived bearer tokens in workflow definitions.
Instructions in Martini
- Register the Sophos Central application and assign minimum required permissions
- Store the client ID and client secret in Martini secrets
- Request and renew bearer tokens through the supported identity flow
- Resolve and retain the authorized tenant context
Objective
Select webhooks for supported low-latency notifications or scheduled workflows for event retrieval, reconciliation, and complete polling-oriented synchronization.
Instructions in Martini
- Confirm whether the required alert or notification category supports webhooks
- Use a protected start-trigger workflow for supported callbacks
- Use a scheduler for alerts, events, endpoint inventory, or reporting jobs
- Define execution limits for long-running paginated work
Objective
Call the applicable Sophos Central REST, event, or SIEM-oriented API and process responses within the relevant tenant and permission scope.
Instructions in Martini
- Call the documented resource with the bearer token
- Handle pagination and page boundaries
- Apply time, cursor, or identifier filters where supported
- Record request context without logging secrets or sensitive payloads
Objective
Coordinate retrieval, validation, transformation, routing, downstream delivery, checkpointing, and failure handling as a maintainable Martini workflow.
Instructions in Martini
- Separate authentication, retrieval, transformation, and delivery concerns
- Route by tenant, severity, product, event type, or endpoint status
- Persist checkpoints and idempotency state in an appropriate store
- Keep downstream writes observable and repeatable
Objective
Normalize Sophos Central’s product-specific JSON objects into canonical models suitable for SIEM, ITSM, CMDB, reporting, or notification destinations.
Instructions in Martini
- Map stable identifiers and preserve source tenant context
- Transform timestamps, severity values, statuses, and relationships
- Retain useful source metadata for investigation and audit
- Allow additive fields without failing on otherwise valid responses
Objective
Apply operational policies before downstream actions, including severity thresholds, tenant boundaries, endpoint retirement logic, and duplicate prevention.
Instructions in Martini
- Filter alerts and events according to business severity rules
- Validate required fields and authorized tenant scope
- Use source alert or event identifiers as idempotency keys
- Distinguish disabled, deleted, unavailable, and out-of-scope objects
Common Sophos Central data objects used in integrations
| Object | Typical Use | Common target systems | Martini handling |
|---|---|---|---|
| Tenants | Represent Sophos Central organizations or customer environments in partner and multi-tenant administration. | Reporting platforms, data warehouses, ServiceNow, CMDBs | Martini retrieves authorized tenant data, preserves tenant scope in the canonical model, and routes records according to permissions and customer context. |
| Endpoints | Represent managed computers and servers protected by Sophos Endpoint. | CMDBs, ITSM platforms, reporting databases, SIEMs | Martini pages through endpoint results, maps identifiers and protection status, reconciles changes, and distinguishes disabled, removed, or out-of-scope endpoints. |
| Endpoint groups | Organize endpoints and associate them with operational or policy groupings. | CMDBs, reporting platforms, ITSM systems | Martini maps group membership and relationship identifiers, preserving tenant context and handling changes during scheduled reconciliation. |
| Alerts | Capture security, health, and operational conditions requiring investigation or action. | ServiceNow, Jira, Microsoft Sentinel, Splunk, Teams, Slack | Martini receives supported notifications or polls the Alerts API, applies severity and product rules, maps alert identifiers, and prevents duplicate downstream actions. |
| Events | Provide security and administrative telemetry for monitoring, investigation, and SIEM processing. | Splunk, Microsoft Sentinel, data stores, monitoring platforms | Martini retrieves events incrementally, transforms them to a common security-event model, forwards them, and advances checkpoints only after successful processing. |
| Policies | Represent configuration governing endpoint, server, device, email, or other Sophos Central services. | Reporting platforms, governance stores, CMDBs | Martini retrieves authorized policy information, normalizes product-specific fields, and produces scheduled compliance or configuration reports. |
Authentication and security considerations
OAuth 2.0 client credentials
Sophos Central APIs use an application client ID and client secret to obtain bearer access tokens. API permissions and tenant scope determine which product areas and operations are available.
Protect credentials and tenant data
- Store client secrets and environment-specific values in Martini secrets or secure configuration.
- Renew expired tokens rather than treating access tokens as permanent credentials.
- Use minimum required Sophos Central permissions and preserve tenant boundaries in multi-tenant workflows.
- Use HTTPS and avoid writing bearer tokens or sensitive event payloads to logs.
Operational considerations for Sophos Central integrations
Pagination and checkpoints
List and event endpoints may paginate responses. Use bounded page processing and persist a timestamp, cursor, or event identifier only after downstream delivery succeeds.
Rate limits and retries
Handle HTTP 429 responses and transient 5xx errors with bounded exponential backoff. Limits can vary by API family, tenant, subscription, or application.
Event coverage and idempotency
Webhook notifications cover selected scenarios rather than every Sophos Central event. Combine callbacks with polling or reconciliation where completeness matters, and use tenant-scoped alert or event identifiers to prevent duplicates.
Schema and product variation
API models vary by product family and may evolve independently. Track API versions, validate required fields, tolerate additive fields, and test against the specific subscription and permissions used in production.
Why use Martini instead of scripts or point-to-point integrations?
Orchestrate more than one API call
Martini coordinates authentication, paginated retrieval, event checkpoints, transformations, business rules, downstream writes, and recovery in one maintainable workflow.
Separate vendor data from target models
Reusable mappings and canonical models reduce point-to-point coupling when Sophos Central data must reach ServiceNow, SIEMs, CMDBs, reporting stores, or notification platforms.
Make operations visible
Structured error handling, retries, validation, logging, and workflow monitoring provide stronger operational control than isolated scripts.
Expose controlled APIs
Martini can expose an API façade for downstream consumers while keeping Sophos Central authentication, tenant rules, transformation logic, and vendor-specific behavior behind a governed integration boundary.
Frequently asked questions
Sophos Central can be integrated through its REST APIs for endpoints, alerts, events, policies, tenants, and product-specific services. Event and SIEM-oriented APIs support scheduled or incremental retrieval, while webhook-style notifications are available for selected alert and notification scenarios. OAuth 2.0 client-credentials authentication is used for API access.
Yes. Martini can integrate with Sophos Central by consuming its REST APIs, retrieving event and SIEM data, authenticating with OAuth 2.0 client credentials, and receiving supported webhook notifications through Martini APIs or workflow triggers. A native Martini Sophos Central connector is not documented in the supplied sources.
No. A dedicated Sophos Central connector is not required. Martini can use Sophos Central’s confirmed REST APIs, OAuth 2.0 authentication, event APIs, and supported webhook mechanisms, while providing the workflow orchestration, mapping, routing, and error handling.
Lonti does not charge an additional per-connector or per-vendor fee to integrate Sophos Central. The integration is subject to the provisioned capacity of the Martini environment. Separate costs may apply from Sophos, cloud infrastructure, SIEM platforms, or other third-party services based on subscription, usage, and deployment model.
REST APIs are the primary method for current integrations. Use event or SIEM-oriented APIs for incremental security-event retrieval and scheduled synchronization. Use webhook-style notifications when the required alert or notification scenario is supported and low latency is important. No official Sophos Central GraphQL or SOAP API was confirmed.
Sophos Central provides event and SIEM-oriented retrieval mechanisms and supports webhook-style integrations for selected alert or notification scenarios. Webhook coverage is not universal, so polling may be required for event categories that are not delivered through callbacks.
Martini can run scheduled workflows that retrieve paginated alerts, events, endpoints, policies, or tenant data. Incremental synchronization should use supported timestamps, cursors, or identifiers, store a checkpoint after successful downstream processing, and use tenant-scoped source identifiers to prevent duplicate records.
Martini can handle expired tokens, authorization failures, HTTP 429 responses, transient 5xx errors, pagination failures, and downstream errors through validation, bounded retries, and monitoring. Stable Sophos Central alert or event identifiers, scoped by tenant and object type when necessary, support idempotent processing.
Related Martini documentation
Connect Sophos Central with your enterprise systems
Use Martini to build governed Sophos Central integrations for alerts, events, endpoints, policies, tenant reporting, and selected webhook notifications.