All Apps and Add-ons

Sophos Central app for Splunk: which Splunk logs should I check to find errors?

dperusich
New Member

Hello,

I've installed, configured, and fixed the typo in sophos_events.py, but the app is not pulling data from Sophos Central/Cloud. Are there any debug settings that can be set, or which Splunk logs should I check to find errors? The API key I'm using works, I've tested it with https://github.com/sophos/Sophos-Central-SIEM-Integration.

Thanks!

0 Karma

sergejreliance
Explorer
  1. $SPLUNK_HOME/var/log/splunk/splunkd.log is good starting point. Search for Sophos or Pyton keywords.
  2. index=_internal will contain same details
0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...