Skip to content

XDR Query API

Run XDR queries against the Sophos Data Lake.

See the guide for a narrative walkthrough of this API.

Base URL

https://api-{dataRegion}.central.sophos.com/xdr-query/v1 — Regional service in the production environment.

Variable Description Default Allowed values
dataRegion Data region where the service is. eu01 eu01, eu02, us01, us03, ca01, au01, jp01, in01, br01, ae01

Authentication

Every request carries an Authorization: Bearer header with an access token obtained through the client-credentials flow — see Get started.

Required permissions

This API's operations require one or more of the following, depending on the operation — see each operation's own page for the exact requirement:

  • xdr.query-catalog:read
  • xdr.query:execute
  • xdr.query:read

Operations

Category

Query

Runs

Download