Sophos Community
Sophos Community
  • User
  • Site
  • Search
  • User
  • Community & Product Forums
  • Blogs
  • Partners
  • Events & Webinars
  • Getting Started
  • Support Portal
  • Community Blogs
    • Application Control
    • Community
    • Product documentation
    • Security
  • Feedback
    • Support Portal
    • Product documentation
  • Products
    • Endpoint security
      • Sophos Endpoint
      • Sophos XDR
      • Device Encryption
      • Sophos Mobile
    • Network Security
      • Sophos Firewall
      • Sophos ZTNA
      • Sophos Switch
      • UTM Firewall
      • Sophos Wireless
      • Sophos NDR
    • Email Security
      • Sophos Email
      • Phish Threat
    • Cloud Security
      • Sophos Central
      • Sophos Cloud Optix
    • Support Tools
      • Sophos integrations
      • Free tools
    • AI Solutions
      • Sophos AI
  • Services
    • Management platform
      • Sophos Professional Services
      • Sophos Central
      • Support Portal
      • Sophos Community log in
  • Sophos Partners
    • Partners blog
    • Local Partner community
    • Partner news
  • Resources
    • MSP guides
    • Partner Care
    • Sophos Central
  • Webinars & Events
    • Webinars & Events
    • Calendar
  • Become a partner
    • Join our program
  • Events & Webinars
    • Events & Webinars
    • Calendar
    • Recordings
  • Getting started in the Community
    • How to get started
    • SophosID registration
    • How to set up your profile
    • How to contribute and participate
    • How to manage private messages
  • Member recognition
    • Recognition program
    • Leaderboard
  • Products and Services
    • Products
      • Endpoint security
        • Sophos Endpoint
        • Sophos XDR
        • Device Encryption
        • Sophos Mobile
      • Network Security
        • Sophos Firewall
        • ZTNA
        • Sophos Switch
        • UTM Firewall
        • Sophos Wireless
        • NDR
      • Email Security
        • Sophos Email
        • Phish Threat
      • Cloud Security
        • Sophos Central
        • Sophos Cloud Optix
      • Support Tools
        • Sophos integrations
        • Free tools
      • AI Solutions
        • Sophos AI
    • Services
      • Management platform
        • Sophos Professional Services
        • Sophos Central
        • Support Portal
        • Sophos Community log in
  • Blogs
    • Community Blogs
      • Application Control
      • Community
      • Product documentation
      • Security
    • Feedback
      • Support Portal
      • Product documentation
  • Partners
    • Sophos Partners
      • Partners blog
      • Local Partner community
      • Partner news
    • Resources
      • MSP guides
      • Partner Care
      • Sophos Central
    • Webinars & Events
      • Webinars & Events
      • Calendar
    • Become a partner
      • Join our program
  • Events & Webinars
    • Events & Webinars
      • Events & Webinars
      • Calendar
      • Recordings
  • Getting Started
    • Getting started in the Community
      • How to get started
      • SophosID registration
      • How to set up your profile
      • How to contribute and participate
      • How to manage private messages
    • Member recognition
      • Recognition program
      • Leaderboard
  • Support Portal
Sophos Integrations
Sophos Integrations
Integrations Splunk apps for Sophos
  • Release Notes & News
  • Integrations
  • Forums
  • Early Access Programs
  • Sophos MSP Program
  • Ideation
  • Members
  • More
  • Cancel
  • New
Sophos Integrations requires membership for participation - click to join
  • -Third Party Integrations
    • +ConnectWise Automate.
    • +Datto RMM
    • N-Able N-Central
    • +NinjaRMM
    • +Sophos integration with Kaseya VSA
    • -Splunk apps for Sophos
      • Splunk Add on for Sophos Central
      • Splunk Add on for Sophos Next-Gen Firewall
    • SynchroMSP
  • Central Partner - Customer CSV

Splunk apps for Sophos

Sophos now offers and supports two Splunk data add-on apps, as well as a dashboard app for visualizing the data across products.

*Note: These installers are provided to our partners and customers "as is" for improving their business processes and conducting threat hunting.  

By using any of the below software, you agree to the Sophos API & Plugins Terms of Use. You also acknowledge that Sophos processes personal data in accordance with the Sophos Privacy Policy.

  • Sophos Firewall Ingestor via syslog forward
  • Sophos Central Data Ingestor
    • Ingests data across
      • Central Endpoints API
      • Central Alerts API
      • Central SIEM Events API
  • Sophos Dashboard App to select data sources and provide insightful dashboards across Central Data, Firewall data, or both if using both Add-ons.
    • Download from Splunkbase.

Note: You must have at least one TA ingestor Add-on as a prerequisite to using the dashboard application.

Dashboard Overview

Threat Dashboard - Use this dashboard to understand threat trends and view threats by type, severity and Source IP over time

  • Correlate data between Central and (XG) Firewall if using both TA Add-ons.

Firewall Overview - Quickly determine usage trends of your firewall device with widgets such as Interface Usage and Web Sessions over time.

 

Web - Provides a snapshot view of web trends and usage over time

Firewall Top 10 - See top trends across application and traffic usage

 

Traffic - Provides a deeper dive into traffic analysis and visualization

Users - View and filter user interactions by time, group, name and IP address

VPN - View VPN trends such as Usage Over Time, Connection Types, and Web Categories accessed via VPN

Installation & Configuration

The dashboard App may be downloaded from Splunkbase.

  • There are configurations on setup to allow you to select dashboard feed from Sophos Central for Endpoint and Alert data, or our Next-Gen firewalls or both.

Note: Once the application is installed you must tell the application what data indexes it should be using as the source from where to display the data.

  • Navigate to "Settings" and click on "Advanced Search"

  • Click on "Search Macros"

  • Select the desired Sophos Search macro for either Sophos Central or Sophos Firewall

  • Enter the name of the index in use within the description field
    • Note: the default value is: index=main

  • Press "Save"

Help & Support

Please post feedback or inquiries to our Feedback forum or email: apis @ sophos.com

  • Splunk Central
  • Splunk Sophos Central
  • Splunk Sophos XG
  • splunk
  • Splunk XG
  • Share
  • History
  • More
  • Cancel

Defeat Cyberattacks

Footer - Default

  • Column 1
    • Endpoint Security
      • Sophos Endpoint
      • Sophos XDR
      • Device Encryption
      • Sophos Mobile
    • Email Security
      • Sophos Email
      • Phish Threat
    • Support Tools
      • Sophos integrations
      • Free tools
  • Column 2
    • Network Security
      • Sophos Firewall
      • Sophos ZTNA
      • Sophos Switch
      • UTM Firewall
      • Sophos Wireless
      • Sophos NDR
    • Cloud Security
      • Sophos Central
      • Sophos Cloud Optix
  • Column 3
    • Partners
      • Find a partner
      • Managed service providers
      • Join our program
    • Current Partners
      • Partners blog
      • Local Partner Community blog
      • Partner MSG guides
      • Partner news
      • Partner care
      • Partner portal login
      • Training & certification
    • Management Platform
      • Sophos Central
  • Column 4
    • Support
      • Downloads and updates
      • Support packages
      • Support portal
      • Sophos Customer Success
      • Sophos Techvids
      • Sophos Learning Center
      • Sophos status
      • Tech support
    • Learn
      • Threat intelligence
      • X-Ops threat research
      • Trust center
      • Security blogs
      • Sophos Academy
  • Column 5
    • Getting Started
      • How to get started
      • Community FAQs
    • Member Recognition
      • Recognition program
      • Leaderboard
    • Events & Webinars
      • Webinars
      • Calendar
      • Recordings
  • Column 6
    • Try for Free
      • Free trials
      • Product demos
    • Sophos Home Premium
      • Sophos Home support
      • Contact Home support
      • Mac antivirus download
      • PC antivirus download
    • About Us
      • Company
      • Events
      • Press
      • Careers
  • Getting Started
  • Terms
  • Privacy
    • Privacy Notice
    • Cookies
  • Legal
    • General
    • Modern Slavery Statement
    • Speak Out
© 1997- Sophos Ltd. All Rights Reserved.