All Apps and Add-ons

Problem with reading objects in Splunk_TA_sophos app

phillip_rice
Explorer

It appears that something may not be correct with this app on my splunk instances. I have the app installed on the indexer and search head, yet it appears not to carry out any of the configuration in props, transforms etc.

When trying to view the objects the contents are not displayed in the GUI, It just opens the object and only displays the cancel and save buttons no data at all.

0 Karma
1 Solution

jcoates_splunk
Splunk Employee
Splunk Employee

the add-on has no visible components, it just does knowledge mapping so that your Sophos data can be used more easily by other apps in the Splunk instance. http://docs.splunk.com/Documentation/AddOns/latest/Sophos/Description for an overview of useful configurations, including how to get your Sophos data into Splunk.

View solution in original post

jcoates_splunk
Splunk Employee
Splunk Employee

the add-on has no visible components, it just does knowledge mapping so that your Sophos data can be used more easily by other apps in the Splunk instance. http://docs.splunk.com/Documentation/AddOns/latest/Sophos/Description for an overview of useful configurations, including how to get your Sophos data into Splunk.

Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...