Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Log data available from Sophos endpoint products for Splunk

Hi,

 

I'm looking to bring in the following endpoint log information from Sophos Cloud to Splunk.  What is the best way to do this:

 

Process Creation events such as:

- Child Command Line

- Child Process

- Child Process Hash

- Host

- Parent Command Line

- Parent Process Hash 

- User

 

Process Network events such as:

- Dest IP

- Process Hash

- Source IP

- Dest Port

- Process Command Line

- Process

- User

- Host

 

File Touch Events such as:

- File Name

- Process Hash

- Host

- File Path

- Process

- User

 

Registry Events such as:

- User

- Process Hash

- Registry Path

- Host

- Process

- Registry Key

- Command Line

 

Thanks

G



This thread was automatically locked due to age.