The details on this app specify "sophos" as the sourcetype for transforms.conf to parse. After working through it, it needs to be "sophos:utm". Please update this in the documentation.
Thank you! Ed
The docs seem to have been updated.
View solution in original post