Deployment Architecture

Sophos Central 1.05 Are there different setup considerations between running on a single server vs. distributed environment.

ewelch_splunk
Splunk Employee
Splunk Employee

We've configured Sophos Central v 1.05 on our dev server and everything works correctly. When we move the same configuration to our production distributed architecture, it fails. We see multiple errors "ERROR ExecProcessor - message from "phython /opt/splunk/etc/apps/sophos_central/bin/sophos_events.ph", and nothing ever hits the firewall. I've seen other questions posted about errors with sophos_events.py and we've verified that those are not our problem. Any Ideas?

0 Karma

nickhills
Ultra Champion

When you say to have moved it to a distributed architecture, what do you mean?

You would want to run the app with a configured account on a single machine like a heavy forwarder, or maybe on your search head.
Be sure to only configure 1 server to perform the collection, lest bad things (like duplication) may happen.

If your installing on multiple servers, it will nag you on each to run the setup - to bypass this add "is_configured = true" in the local/app.conf .

Maybe i'll add that option in 1.0.6

If my comment helps, please give it a thumbs up!
0 Karma
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...