All Apps and Add-ons

Problem with reading objects in Splunk_TA_sophos app

phillip_rice
Explorer

It appears that something may not be correct with this app on my splunk instances. I have the app installed on the indexer and search head, yet it appears not to carry out any of the configuration in props, transforms etc.

When trying to view the objects the contents are not displayed in the GUI, It just opens the object and only displays the cancel and save buttons no data at all.

0 Karma
1 Solution

jcoates_splunk
Splunk Employee
Splunk Employee

the add-on has no visible components, it just does knowledge mapping so that your Sophos data can be used more easily by other apps in the Splunk instance. http://docs.splunk.com/Documentation/AddOns/latest/Sophos/Description for an overview of useful configurations, including how to get your Sophos data into Splunk.

View solution in original post

jcoates_splunk
Splunk Employee
Splunk Employee

the add-on has no visible components, it just does knowledge mapping so that your Sophos data can be used more easily by other apps in the Splunk instance. http://docs.splunk.com/Documentation/AddOns/latest/Sophos/Description for an overview of useful configurations, including how to get your Sophos data into Splunk.

Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...