All Apps and Add-ons

Getting checkpointer error for alerts in Sophos Add-on for splunk

ajaycitrus
New Member

I have installed the Sophos on Add for Splunk (https://splunkbase.splunk.com/app/4096/ ) on HF

I am able to receive the events perfectly but i get the below error when i configure it to pull alerts:

2020-03-05 11:52:19,263 ERROR pid=176598 tid=MainThread file=base_modinput.py:log_error:307 |
{"has_more":false,"next_cursor":"xxxxxxxxLTAzLTA1VDEwOjUyOjE5LjIwM1o=","items":[]}

0 Karma

eegiievol
Explorer

Could you please help me. Is there anything else I have to modify except inputs.conf. I have trouble getting data onboard. 

0 Karma

konstr
Path Finder

I am having the exact same issue, did you manage to figure it out?

0 Karma

ajaycitrus
New Member

I have upgraded to the latest version.

Now, its polls data one-twice in a day although polling interval is set at 30 seconds.
Most of the times, it fails but once or twice, the request goes through and pulls all the data ( there is no gap in the data)

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...