All Apps and Add-ons

Problem with reading objects in Splunk_TA_sophos app

Explorer

It appears that something may not be correct with this app on my splunk instances. I have the app installed on the indexer and search head, yet it appears not to carry out any of the configuration in props, transforms etc.

When trying to view the objects the contents are not displayed in the GUI, It just opens the object and only displays the cancel and save buttons no data at all.

0 Karma
1 Solution

Splunk Employee
Splunk Employee

the add-on has no visible components, it just does knowledge mapping so that your Sophos data can be used more easily by other apps in the Splunk instance. http://docs.splunk.com/Documentation/AddOns/latest/Sophos/Description for an overview of useful configurations, including how to get your Sophos data into Splunk.

View solution in original post

Splunk Employee
Splunk Employee

the add-on has no visible components, it just does knowledge mapping so that your Sophos data can be used more easily by other apps in the Splunk instance. http://docs.splunk.com/Documentation/AddOns/latest/Sophos/Description for an overview of useful configurations, including how to get your Sophos data into Splunk.

View solution in original post