<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Missed data from SOPHOS in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Missed-data-from-SOPHOS/m-p/709561#M117222</link>
    <description>&lt;P&gt;I am encountering an issue regarding the synchronization of update logs between Sophos and Splunk for a specific host, designated as "EXAMPLE01." According to the Sophos console, the device has received updates on the following dates:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;19 Nov 2024&lt;/LI&gt;&lt;LI&gt;20 Nov 2024&lt;/LI&gt;&lt;LI&gt;26 Nov 2024&lt;/LI&gt;&lt;LI&gt;2 Dec 2024&lt;/LI&gt;&lt;LI&gt;3 Dec 2024&lt;/LI&gt;&lt;LI&gt;10 Dec 2024&lt;/LI&gt;&lt;LI&gt;17 Dec 2024&lt;/LI&gt;&lt;LI&gt;21 Jan 2025&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;However, when I search in Splunk within the same timeframe (1 Nov 2024 to 23 Jan 2025), the logs only show updates on:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;3 Dec 2024&lt;/LI&gt;&lt;LI&gt;10 Dec 2024&lt;/LI&gt;&lt;LI&gt;17 Dec 2024&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;I aim to establish a rule that triggers a notification if there has been no update for 20 days or more. Regrettably, despite the Sophos console indicating recent updates, the discrepancies in Splunk raise concerns about accurate monitoring.&lt;/P&gt;&lt;P&gt;I have verified the settings under Indexing &amp;gt; Indexes and Volumes in Splunk, and everything appears to be configured correctly. Could anyone provide insights on how to track and resolve this discrepancy?&lt;/P&gt;&lt;P&gt;Thank you for your assistance.&lt;/P&gt;</description>
    <pubDate>Thu, 23 Jan 2025 07:24:48 GMT</pubDate>
    <dc:creator>zksvc</dc:creator>
    <dc:date>2025-01-23T07:24:48Z</dc:date>
    <item>
      <title>Missed data from SOPHOS</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Missed-data-from-SOPHOS/m-p/709561#M117222</link>
      <description>&lt;P&gt;I am encountering an issue regarding the synchronization of update logs between Sophos and Splunk for a specific host, designated as "EXAMPLE01." According to the Sophos console, the device has received updates on the following dates:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;19 Nov 2024&lt;/LI&gt;&lt;LI&gt;20 Nov 2024&lt;/LI&gt;&lt;LI&gt;26 Nov 2024&lt;/LI&gt;&lt;LI&gt;2 Dec 2024&lt;/LI&gt;&lt;LI&gt;3 Dec 2024&lt;/LI&gt;&lt;LI&gt;10 Dec 2024&lt;/LI&gt;&lt;LI&gt;17 Dec 2024&lt;/LI&gt;&lt;LI&gt;21 Jan 2025&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;However, when I search in Splunk within the same timeframe (1 Nov 2024 to 23 Jan 2025), the logs only show updates on:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;3 Dec 2024&lt;/LI&gt;&lt;LI&gt;10 Dec 2024&lt;/LI&gt;&lt;LI&gt;17 Dec 2024&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;I aim to establish a rule that triggers a notification if there has been no update for 20 days or more. Regrettably, despite the Sophos console indicating recent updates, the discrepancies in Splunk raise concerns about accurate monitoring.&lt;/P&gt;&lt;P&gt;I have verified the settings under Indexing &amp;gt; Indexes and Volumes in Splunk, and everything appears to be configured correctly. Could anyone provide insights on how to track and resolve this discrepancy?&lt;/P&gt;&lt;P&gt;Thank you for your assistance.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jan 2025 07:24:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Missed-data-from-SOPHOS/m-p/709561#M117222</guid>
      <dc:creator>zksvc</dc:creator>
      <dc:date>2025-01-23T07:24:48Z</dc:date>
    </item>
  </channel>
</rss>

