All Apps and Add-ons

Problem with reading objects in Splunk_TA_sophos app

phillip_rice
Explorer

It appears that something may not be correct with this app on my splunk instances. I have the app installed on the indexer and search head, yet it appears not to carry out any of the configuration in props, transforms etc.

When trying to view the objects the contents are not displayed in the GUI, It just opens the object and only displays the cancel and save buttons no data at all.

0 Karma
1 Solution

jcoates_splunk
Splunk Employee
Splunk Employee

the add-on has no visible components, it just does knowledge mapping so that your Sophos data can be used more easily by other apps in the Splunk instance. http://docs.splunk.com/Documentation/AddOns/latest/Sophos/Description for an overview of useful configurations, including how to get your Sophos data into Splunk.

View solution in original post

jcoates_splunk
Splunk Employee
Splunk Employee

the add-on has no visible components, it just does knowledge mapping so that your Sophos data can be used more easily by other apps in the Splunk instance. http://docs.splunk.com/Documentation/AddOns/latest/Sophos/Description for an overview of useful configurations, including how to get your Sophos data into Splunk.

Get Updates on the Splunk Community!

Observability | How to Think About Instrumentation Overhead (White Paper)

Novice observability practitioners are often overly obsessed with performance. They might approach ...

Cloud Platform | Get Resiliency in the Cloud Event (Register Now!)

IDC Report: Enterprises Gain Higher Efficiency and Resiliency With Migration to Cloud  Today many enterprises ...

The Great Resilience Quest: 10th Leaderboard Update

The tenth leaderboard update (11.23-12.05) for The Great Resilience Quest is out >> As our brave ...