All Apps and Add-ons

Why does the Rest API input for Sophos Central app doesn't index with correct parameters?

brian1_tate
Path Finder

I've installed the Sophos Central API TA and configured with appropriate fields. I have even tested this with their python script and I was able to return results. However, if I search the Sophos index or view it in Data Summary, there are not sources or sourcetypes. This is a single instance and I found that I had issues with my first data source of meraki over syslog because there was no inputs.conf in the local directory. Adding it with the appropriate line resolved this and the respective TA was able to index and I was able to search that data.

Is there something I am missing in the inputs.conf file that is needed for the Sophos Central TA to function?

Like, is there some line line restapi:/// or something that I need to add to get Splunk to realize that the app is installed with correct auth and header info?

I've looked at Sophos video which really isn't helpful and I have reviewed some of the app dev's comments but those did not answer this question. Assuming I wanted to add any restful API for a GET (not to POST into Splunk), what would I need to do with the inputs.conf file to get Splunk to understand that I added an input in the UI?

0 Karma

nickhills
Ultra Champion

Hi There, I am the original creator of this app.

I have just posed this notice as Sophos have released their own supported version of this App.

I am unable to easily support the old application as I no longer have access to a Sophos Central Subscription.
Thanks for your support, but your most reliable future path is probably with the new Sophos app as they will be able to better support you today and in the future.

If you have any questions, feel free to ask.
Happy Splunking

Nick

If my comment helps, please give it a thumbs up!
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...

SPL2 Deep Dives, AppDynamics Integrations, SAML Made Simple and Much More on Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...