Hi @helixsam ,
I am using this Sophos app on SH but it was created by me.
I have installed Sophos add-on for Splunk on HF. This is one way you can do.
Or if you have valid Sophos admin access with valid license, you can follow the SIEM integration guide provided in Github and do the integration.
There are couple of files you will have to change (config.ini and siem.py scripts for key and time params respectively).
Use task scheduler to get the log file in logs folder.
Configure inputs.conf to monitor the logs folder.
Please let me know if you need more help on this.
Regards,
Tejas
... View more