All Apps and Add-ons

In a SHC Deployment, where does the logs stored - Sophos Central

aruncp333
Explorer

I have Splunk ES Setup and I can see the logs coming from Sophos Central onto the Search Head(where I installed the app).
I would like to know where these logs are stored in Splunk. I have tried to find logs on indexers but it wasn't.

0 Karma

FrankVl
Ultra Champion

It might be indexed locally on the search head that does the API calls. Doesn't sound like something you want especially in a SH cluster.

Typically in distributed/clustered environments these kinds of API data collection methods are ran from a Heavy Forwarder that then sends it to the indexers.

Also, that app you mention (assuming you tagged the correct app) is deprecated. Have a look at these instead.

TA Sophos Add-on for Splunk https://splunkbase.splunk.com/app/4096/
APP Sophos App for Splunk https://splunkbase.splunk.com/app/4097/

0 Karma

tiagofbmm
Influencer

App logs as other logs are stored under $SPLUNK_HOME/var/log/splunk

0 Karma
Get Updates on the Splunk Community!

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...