I don't see any usernames populating and would like to know if there is a way to carry that information from central. All users appear as $splunk_home/etc/apps/sophos_central/bin/sophos_events.py
Thanks, Mike