All Apps and Add-ons

Sophos Central App for Splunk problems in clustered environment

mfleitma
Explorer

I have set up a new splunk test environment with search head cluster (3 SH) and index cluster (2 IDX).

Also added Splunk_SA_CIM first in version 4.18, in my latest test version 4.20.2.

Splunk is working fine, acclerated DM are working, which means they are searchable.

After installing the sophos Central app https://splunkbase.splunk.com/app/6186/ I'm not able to search in my datamodel:

| datamodel Authentication search

mfleitma_0-1638971326564.png

 

More simple:

searching with tag is not working, index=* tag=authentication has the same error.

Tested on a single splunk without problems.

??

0 Karma

mfleitma
Explorer

Has anyone solved running the app succesfully on a splunk cluster system?

0 Karma

mfleitma
Explorer

More information:

splunk installation version 8.1.4

even the configuration within the app sophos central for loglevel, proxy, settings and the input are not propagated automatically to the other search heads in the cluster.

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...