All Apps and Add-ons

Sophos Central App for Splunk problems in clustered environment

mfleitma
Explorer

I have set up a new splunk test environment with search head cluster (3 SH) and index cluster (2 IDX).

Also added Splunk_SA_CIM first in version 4.18, in my latest test version 4.20.2.

Splunk is working fine, acclerated DM are working, which means they are searchable.

After installing the sophos Central app https://splunkbase.splunk.com/app/6186/ I'm not able to search in my datamodel:

| datamodel Authentication search

mfleitma_0-1638971326564.png

 

More simple:

searching with tag is not working, index=* tag=authentication has the same error.

Tested on a single splunk without problems.

??

0 Karma

mfleitma
Explorer

Has anyone solved running the app succesfully on a splunk cluster system?

0 Karma

mfleitma
Explorer

More information:

splunk installation version 8.1.4

even the configuration within the app sophos central for loglevel, proxy, settings and the input are not propagated automatically to the other search heads in the cluster.

0 Karma
Get Updates on the Splunk Community!

Observability Unlocked: Kubernetes Monitoring with Splunk Observability Cloud

  Ready to master Kubernetes and cloud monitoring like the pros?Join Splunk’s Growth Engineering team for an ...

Wrapping Up Cybersecurity Awareness Month

October might be wrapping up, but for Splunk Education, cybersecurity awareness never goes out of season. ...

🌟 From Audit Chaos to Clarity: Welcoming Audit Trail v2

🗣 You Spoke, We Listened  Audit Trail v2 wasn’t written in isolation—it was shaped by your voices.  In ...