<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Why is my sophos dashboard not showing data? in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/Why-is-my-sophos-dashboard-not-showing-data/m-p/641167#M52347</link>
    <description>&lt;P&gt;I have sophos and sonicwall firewall in my network and installed splunk for log gathering. Then I configured sophos in splunk, collecting all logs from sophos. But showing no data in sophos dashboard.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please guide me to get sophos all alerts in dash&lt;/P&gt;</description>
    <pubDate>Tue, 25 Apr 2023 15:23:33 GMT</pubDate>
    <dc:creator>madhuys</dc:creator>
    <dc:date>2023-04-25T15:23:33Z</dc:date>
    <item>
      <title>Why is my sophos dashboard not showing data?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Why-is-my-sophos-dashboard-not-showing-data/m-p/641167#M52347</link>
      <description>&lt;P&gt;I have sophos and sonicwall firewall in my network and installed splunk for log gathering. Then I configured sophos in splunk, collecting all logs from sophos. But showing no data in sophos dashboard.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please guide me to get sophos all alerts in dash&lt;/P&gt;</description>
      <pubDate>Tue, 25 Apr 2023 15:23:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Why-is-my-sophos-dashboard-not-showing-data/m-p/641167#M52347</guid>
      <dc:creator>madhuys</dc:creator>
      <dc:date>2023-04-25T15:23:33Z</dc:date>
    </item>
    <item>
      <title>Re: sophos dashboard</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Why-is-my-sophos-dashboard-not-showing-data/m-p/641178#M52350</link>
      <description>&lt;P&gt;Installing an app and collecting logs is not unlike digging a tunnel from both ends.&amp;nbsp; If you're not careful, the ends won't meet.&lt;/P&gt;&lt;P&gt;No doubt the Sophos dashboard is looking for specific data in a specific place.&amp;nbsp; Did you put your logs in the right place (index)?&amp;nbsp; Do your logs have the data the dashboard is looking for?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Check the timestamps on the logs because if they're incorrect then Splunk won't find the data.&amp;nbsp; For&amp;nbsp; instance, if the time zone is off then events may be indexed "in the future".&lt;/P&gt;&lt;P&gt;You may need to read the dashboard code to see exactly what is being sought.&lt;/P&gt;</description>
      <pubDate>Mon, 24 Apr 2023 18:35:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Why-is-my-sophos-dashboard-not-showing-data/m-p/641178#M52350</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-04-24T18:35:26Z</dc:date>
    </item>
    <item>
      <title>Re: sophos dashboard</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Why-is-my-sophos-dashboard-not-showing-data/m-p/641208#M52351</link>
      <description>&lt;P&gt;Thanks for the replay.&amp;nbsp; I have followed the mentioned URL. it is fetching logs from sophos firewall. I'm missing something here. please guide.&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.sophos.com/sophos-integrations/w/integrations/106/splunk-add-on-for-sophos-next-gen-firewall" target="_blank"&gt;https://community.sophos.com/sophos-integrations/w/integrations/106/splunk-add-on-for-sophos-next-gen-firewall&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Apr 2023 05:05:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Why-is-my-sophos-dashboard-not-showing-data/m-p/641208#M52351</guid>
      <dc:creator>madhuys</dc:creator>
      <dc:date>2023-04-25T05:05:28Z</dc:date>
    </item>
    <item>
      <title>Re: sophos dashboard</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Why-is-my-sophos-dashboard-not-showing-data/m-p/641270#M52356</link>
      <description>&lt;P&gt;As I stated previously, ingesting data is only part of the puzzle.&amp;nbsp; Have you examined the app to see what data it expects and where it expects to find it?&amp;nbsp; Do you have the data the app is expecting?&lt;/P&gt;</description>
      <pubDate>Tue, 25 Apr 2023 12:24:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Why-is-my-sophos-dashboard-not-showing-data/m-p/641270#M52356</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-04-25T12:24:23Z</dc:date>
    </item>
    <item>
      <title>Re: sophos dashboard</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Why-is-my-sophos-dashboard-not-showing-data/m-p/642493#M52471</link>
      <description>&lt;P&gt;Thanks for support. I tried to find the problem but failed.&amp;nbsp; How to diagnose line by line to identify the&amp;nbsp; problem.&lt;/P&gt;</description>
      <pubDate>Sun, 07 May 2023 17:57:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Why-is-my-sophos-dashboard-not-showing-data/m-p/642493#M52471</guid>
      <dc:creator>madhuys</dc:creator>
      <dc:date>2023-05-07T17:57:47Z</dc:date>
    </item>
    <item>
      <title>Re: sophos dashboard</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Why-is-my-sophos-dashboard-not-showing-data/m-p/642494#M52472</link>
      <description>&lt;P&gt;HOW did you try to solve the problem?&lt;/P&gt;&lt;P&gt;This probably is not a line-by-line debugging scenario.&amp;nbsp; This is a case of examining the search(es) used by the dashboard and confirming you have the data sought by the search.&lt;/P&gt;&lt;P&gt;Use the Edit button to open the dashboard then click the magnifying glass icon to see the search query.&amp;nbsp; Copy that query into a separate search tab/window.&amp;nbsp; Set the time range to match that used by the dashboard.&amp;nbsp; Remove everything from the first pipe (|) to the end of the query and run the search.&amp;nbsp; Verify you get results.&amp;nbsp; If you don't then something in the new query doesn't match your data and will have to be modified.&lt;/P&gt;&lt;P&gt;If you do get results, then add the pipe and command from the original query and run the search again.&amp;nbsp; Verify you get results.&amp;nbsp; Repeat this process until you get no results.&amp;nbsp; That command will be the one causing the problem.&amp;nbsp; Modify that command so it works with the data you have.&amp;nbsp; Copy the resulting query back to the dashboard.&lt;/P&gt;</description>
      <pubDate>Sun, 07 May 2023 18:59:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Why-is-my-sophos-dashboard-not-showing-data/m-p/642494#M52472</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-05-07T18:59:05Z</dc:date>
    </item>
  </channel>
</rss>

