All Apps and Add-ons

Is there a way to pull the Sophos Audit Logs as well?

Sparky1
Explorer

If i go to Logs & Reports, in the sophos central console, under the General Logs heading there are 2 options, Events and Audit Logs. Based on the information that is polled from the Splunk Add-on only the Event Logs are polled, is there a way to receive the Audit Logs as well?

mon123
Engager

@Sparky1 were you able to find out the solution to ingest Sophos audit logs ?

0 Karma

osakachan
Communicator

Hello,

Ingesting machine data from Sophos Central you will have 2 kinds of logs with 2 differents customer_id (it is only same alphanumeric but rearranged). One of them gives you extended information about one of the events with the other customer_id.

This is using this https://github.com/sophos/Sophos-Central-SIEM-Integration

0 Karma

mstjohn_splunk
Splunk Employee
Splunk Employee

hi @sparky1,

Thanks for posting.

Could you give us some more context for your query? You have a much better chance of getting your question answered if you provide more information about your issue. Plus, it will help guide future community users who are facing a similar problem.

0 Karma
Get Updates on the Splunk Community!

Splunk Edge Processor | Popular Use Cases to Get Started with Edge Processor

Splunk Edge Processor offers more efficient, flexible data transformation – helping you reduce noise, control ...

Introducing New Splunkbase Governance!

Splunk apps are essential for maximizing the value of your Splunk Experience. Whether you’re using the default ...

3 Ways to Make OpenTelemetry Even Better

My role as an Observability Specialist at Splunk provides me with the opportunity to work with customers of ...