All Apps and Add-ons

Sophos Central App For Splunk Cloud

helixsam
New Member

Hi,

I can't find the Sophos Central App for Splunk Cloud.
I've found the SOPHOS CENTRAL SIEM INTEGRATION on the catalog, filtering for Splunk Cloud, but is not present in the App search on my instance.
I'm on trial version, can be a license issue?

Thank you

0 Karma

tbavarva
Path Finder

Hi @helixsam ,
I am using this Sophos app on SH but it was created by me.

I have installed Sophos add-on for Splunk on HF. This is one way you can do.

Or if you have valid Sophos admin access with valid license, you can follow the SIEM integration guide provided in Github and do the integration.

  1. There are couple of files you will have to change (config.ini and siem.py scripts for key and time params respectively).
  2. Use task scheduler to get the log file in logs folder.
  3. Configure inputs.conf to monitor the logs folder.

Please let me know if you need more help on this.

Regards,
Tejas

0 Karma

DavidHourani
Super Champion

Hi @helixsam,

Are you referring to the TA : https://splunkbase.splunk.com/app/4647/#/details

Would be best to reach out to support in case the app requires some system configuration.

Cheers,
David

0 Karma
Get Updates on the Splunk Community!

Observability | Use Synthetic Monitoring for Website Metadata Verification

If you are on Splunk Observability Cloud, you may already have Synthetic Monitoringin your observability ...

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...