Hi,
I can't find the Sophos Central App for Splunk Cloud.
I've found the SOPHOS CENTRAL SIEM INTEGRATION on the catalog, filtering for Splunk Cloud, but is not present in the App search on my instance.
I'm on trial version, can be a license issue?
Thank you
Hi @helixsam ,
I am using this Sophos app on SH but it was created by me.
I have installed Sophos add-on for Splunk on HF. This is one way you can do.
Or if you have valid Sophos admin access with valid license, you can follow the SIEM integration guide provided in Github and do the integration.
Please let me know if you need more help on this.
Regards,
Tejas
Hi @helixsam,
Are you referring to the TA : https://splunkbase.splunk.com/app/4647/#/details
Would be best to reach out to support in case the app requires some system configuration.
Cheers,
David