All Apps and Add-ons

Why does the Rest API input for Sophos Central app doesn't index with correct parameters?

brian1_tate
Path Finder

I've installed the Sophos Central API TA and configured with appropriate fields. I have even tested this with their python script and I was able to return results. However, if I search the Sophos index or view it in Data Summary, there are not sources or sourcetypes. This is a single instance and I found that I had issues with my first data source of meraki over syslog because there was no inputs.conf in the local directory. Adding it with the appropriate line resolved this and the respective TA was able to index and I was able to search that data.

Is there something I am missing in the inputs.conf file that is needed for the Sophos Central TA to function?

Like, is there some line line restapi:/// or something that I need to add to get Splunk to realize that the app is installed with correct auth and header info?

I've looked at Sophos video which really isn't helpful and I have reviewed some of the app dev's comments but those did not answer this question. Assuming I wanted to add any restful API for a GET (not to POST into Splunk), what would I need to do with the inputs.conf file to get Splunk to understand that I added an input in the UI?

0 Karma

nickhills
Ultra Champion

Hi There, I am the original creator of this app.

I have just posed this notice as Sophos have released their own supported version of this App.

I am unable to easily support the old application as I no longer have access to a Sophos Central Subscription.
Thanks for your support, but your most reliable future path is probably with the new Sophos app as they will be able to better support you today and in the future.

If you have any questions, feel free to ask.
Happy Splunking

Nick

If my comment helps, please give it a thumbs up!
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...