Hi All,
We got our Splunk deployment done from a 3rd party, which has completed the deployment and left already. Suddenly, Sophos central logs have stopped coming to splunk, for last 3 months. I have checked the API keys at sophos, they are still valid. (The logs are integrated through sophos API).
I have the following questions, if somebody can help me with these
1- Where to check in splunk, the configuration done to read the sophos logs? I can't even find out where the splunk side settings are done to capture these logs.
2- How to troubleshoot this issue?
Thanks.