All Apps and Add-ons

Sophos Central App for Splunk problems in clustered environment

mfleitma
Explorer

I have set up a new splunk test environment with search head cluster (3 SH) and index cluster (2 IDX).

Also added Splunk_SA_CIM first in version 4.18, in my latest test version 4.20.2.

Splunk is working fine, acclerated DM are working, which means they are searchable.

After installing the sophos Central app https://splunkbase.splunk.com/app/6186/ I'm not able to search in my datamodel:

| datamodel Authentication search

mfleitma_0-1638971326564.png

 

More simple:

searching with tag is not working, index=* tag=authentication has the same error.

Tested on a single splunk without problems.

??

0 Karma

mfleitma
Explorer

Has anyone solved running the app succesfully on a splunk cluster system?

0 Karma

mfleitma
Explorer

More information:

splunk installation version 8.1.4

even the configuration within the app sophos central for loglevel, proxy, settings and the input are not propagated automatically to the other search heads in the cluster.

0 Karma
Get Updates on the Splunk Community!

🌟 From Audit Chaos to Clarity: Welcoming Audit Trail v2

🗣 You Spoke, We Listened  Audit Trail v2 wasn’t written in isolation—it was shaped by your voices.  In ...

What's New in Splunk Observability - October 2025

What’s New?    We’re excited to announce the latest enhancements to Splunk Observability Cloud and share ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

 Prepare to elevate your security operations with the powerful upgrade to Splunk Enterprise Security 8.x! This ...