All Apps and Add-ons

Why does the Rest API input for Sophos Central app doesn't index with correct parameters?

brian1_tate
Path Finder

I've installed the Sophos Central API TA and configured with appropriate fields. I have even tested this with their python script and I was able to return results. However, if I search the Sophos index or view it in Data Summary, there are not sources or sourcetypes. This is a single instance and I found that I had issues with my first data source of meraki over syslog because there was no inputs.conf in the local directory. Adding it with the appropriate line resolved this and the respective TA was able to index and I was able to search that data.

Is there something I am missing in the inputs.conf file that is needed for the Sophos Central TA to function?

Like, is there some line line restapi:/// or something that I need to add to get Splunk to realize that the app is installed with correct auth and header info?

I've looked at Sophos video which really isn't helpful and I have reviewed some of the app dev's comments but those did not answer this question. Assuming I wanted to add any restful API for a GET (not to POST into Splunk), what would I need to do with the inputs.conf file to get Splunk to understand that I added an input in the UI?

0 Karma

nickhills
Ultra Champion

Hi There, I am the original creator of this app.

I have just posed this notice as Sophos have released their own supported version of this App.

I am unable to easily support the old application as I no longer have access to a Sophos Central Subscription.
Thanks for your support, but your most reliable future path is probably with the new Sophos app as they will be able to better support you today and in the future.

If you have any questions, feel free to ask.
Happy Splunking

Nick

If my comment helps, please give it a thumbs up!
0 Karma
Get Updates on the Splunk Community!

Accelerate Service Onboarding, Decomposition, Troubleshooting - and more with ITSI’s ...

Accelerate Service Onboarding, Decomposition, Troubleshooting - and more! Faster Time to ValueManaging and ...

New Release | Splunk Enterprise 9.3

Admins and Analyst can benefit from:  Seamlessly route data to your local file system to save on storage ...

2024 Splunk Career Impact Survey | Earn a $20 gift card for participating!

Hear ye, hear ye! The time has come again for Splunk's annual Career Impact Survey!  We need your help by ...