All Apps and Add-ons

Sophos Central app for Splunk: which Splunk logs should I check to find errors?

dperusich
New Member

Hello,

I've installed, configured, and fixed the typo in sophos_events.py, but the app is not pulling data from Sophos Central/Cloud. Are there any debug settings that can be set, or which Splunk logs should I check to find errors? The API key I'm using works, I've tested it with https://github.com/sophos/Sophos-Central-SIEM-Integration.

Thanks!

0 Karma

sergejreliance
Explorer
  1. $SPLUNK_HOME/var/log/splunk/splunkd.log is good starting point. Search for Sophos or Pyton keywords.
  2. index=_internal will contain same details
0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...