Hi,
I'm looking to bring in the following endpoint log information from Sophos Cloud to Splunk. What is the best way to do this:
Process Creation events such as:
- Child Command Line
- Child Process
- Child Process Hash
- Host
- Parent Command Line
- Parent Process Hash
- User
Process Network events such as:
- Dest IP
- Process Hash
- Source IP
- Dest Port
- Process Command Line
- Process
- User
- Host
File Touch Events such as:
- File Name
- Process Hash
- Host
- File Path
- Process
- User
Registry Events such as:
- User
- Process Hash
- Registry Path
- Host
- Process
- Registry Key
- Command Line
Thanks
G
This thread was automatically locked due to age.