All Apps and Add-ons

Sophos App - JSON fields renaming

JScordo
Path Finder

After installing the add-on and getting data into my environment from the Sophos Add-On For Splunk (https://splunkbase.splunk.com/app/4096/) I noticed that the json comes with a field named "source" which causes issues since when setting the inputs Splunk determines the source as the "Customer Name or Account ID". This causes each event to have multiple values for the field "source". Can the developers of the add-on change the name of that json field to anything other than the 4 main fields Splunk uses? source_host would be a better name for it.

TYIA,
Joe

0 Karma

eegiievol
Explorer

Could you please help me. Is there anything else I have to modify except inputs.conf. I have trouble getting data onboard. 

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...