category: Data Enrichment & Threat Intelligence provider: Thoma Bravo sectionorder: - Connect - Collect commonfields: id: Sophos Central version: -1 configuration: - display: Client ID displaypassword: Client Secret name: credentials type: 9 required: true additionalinfo: The Sophos account secret should be in the password field. section: Connect - display: Tenant ID name: tenant_id additionalinfo: Tenant ID on which the commands would be executed by default. Keep it empty if using tenant level credentials. type: 0 section: Connect required: false - display: Fetch incidents name: isFetch type: 8 required: false section: Collect - additionalinfo: Choose the severity(s) (not minimum) to fetch. If none is chosen, all severity levels will be returned. display: Fetch Severity section: Collect name: fetch_severity options: - low - medium - high type: 16 required: false - additionalinfo: Choose one or more categories to fetch. If none is chosen, all categories will be returned. display: Fetch Category name: fetch_category options: - azure - adSync - applicationControl - appReputation - blockListed - connectivity - cwg - denc - downloadReputation - endpointFirewall - fenc - forensicSnapshot - general - iaas - iaasAzure - isolation - malware - mtr - mobiles - policy - protection - pua - runtimeDetections - security - smc - systemHealth - uav - uncategorized - updating - utm - virt - wireless - xgEmail type: 16 section: Collect advanced: true required: false - additionalinfo: Maximum number of alerts per fetch. Default is 50. Maximum is 100. defaultvalue: '50' display: Fetch Limit name: max_fetch type: 0 section: Collect required: false - defaultvalue: 7 days display: First fetch timestamp (