All Apps and Add-ons

Is there a way to pull the Sophos Audit Logs as well?

Sparky1
Explorer

If i go to Logs & Reports, in the sophos central console, under the General Logs heading there are 2 options, Events and Audit Logs. Based on the information that is polled from the Splunk Add-on only the Event Logs are polled, is there a way to receive the Audit Logs as well?

mon123
Engager

@Sparky1 were you able to find out the solution to ingest Sophos audit logs ?

0 Karma

osakachan
Communicator

Hello,

Ingesting machine data from Sophos Central you will have 2 kinds of logs with 2 differents customer_id (it is only same alphanumeric but rearranged). One of them gives you extended information about one of the events with the other customer_id.

This is using this https://github.com/sophos/Sophos-Central-SIEM-Integration

0 Karma

mstjohn_splunk
Splunk Employee
Splunk Employee

hi @sparky1,

Thanks for posting.

Could you give us some more context for your query? You have a much better chance of getting your question answered if you provide more information about your issue. Plus, it will help guide future community users who are facing a similar problem.

0 Karma
Get Updates on the Splunk Community!

Cultivate Your Career Growth with Fresh Splunk Training

Growth doesn’t just happen—it’s nurtured. Like tending a garden, developing your Splunk skills takes the right ...

Introducing a Smarter Way to Discover Apps on Splunkbase

We’re excited to announce the launch of a foundational enhancement to Splunkbase: App Tiering.  Because we’ve ...

How to Send Splunk Observability Alerts to Webex teams in Minutes

As a Developer Evangelist at Splunk, my team and I are constantly tinkering with technology to explore its ...