Sophos Community
Sophos Community
  • User
  • Site
  • Search
  • User
  • Community & Product Forums
  • Blogs
  • Partners
  • Events & Webinars
  • Getting Started
  • Support Portal
  • Community Blogs
    • Application Control
    • Community
    • Product documentation
    • Security
  • Feedback
    • Support Portal
    • Product documentation
  • Products
    • Endpoint security
      • Sophos Endpoint
      • Sophos XDR
      • Device Encryption
      • Sophos Mobile
    • Network Security
      • Sophos Firewall
      • Sophos ZTNA
      • Sophos Switch
      • UTM Firewall
      • Sophos Wireless
      • Sophos NDR
    • Email Security
      • Sophos Email
      • Phish Threat
    • Cloud Security
      • Sophos Central
      • Sophos Cloud Optix
    • Support Tools
      • Sophos integrations
      • Free tools
    • AI Solutions
      • Sophos AI
  • Services
    • Management platform
      • Sophos Professional Services
      • Sophos Central
      • Support Portal
      • Sophos Community log in
  • Sophos Partners
    • Partners blog
    • Local Partner community
    • Partner news
  • Resources
    • MSP guides
    • Partner Care
    • Sophos Central
  • Webinars & Events
    • Webinars & Events
    • Calendar
  • Become a partner
    • Join our program
  • Events & Webinars
    • Events & Webinars
    • Calendar
    • Recordings
  • Getting started in the Community
    • How to get started
    • SophosID registration
    • How to set up your profile
    • How to contribute and participate
    • How to manage private messages
  • Member recognition
    • Recognition program
    • Leaderboard
  • Products and Services
    • Products
      • Endpoint security
        • Sophos Endpoint
        • Sophos XDR
        • Device Encryption
        • Sophos Mobile
      • Network Security
        • Sophos Firewall
        • ZTNA
        • Sophos Switch
        • UTM Firewall
        • Sophos Wireless
        • NDR
      • Email Security
        • Sophos Email
        • Phish Threat
      • Cloud Security
        • Sophos Central
        • Sophos Cloud Optix
      • Support Tools
        • Sophos integrations
        • Free tools
      • AI Solutions
        • Sophos AI
    • Services
      • Management platform
        • Sophos Professional Services
        • Sophos Central
        • Support Portal
        • Sophos Community log in
  • Blogs
    • Community Blogs
      • Application Control
      • Community
      • Product documentation
      • Security
    • Feedback
      • Support Portal
      • Product documentation
  • Partners
    • Sophos Partners
      • Partners blog
      • Local Partner community
      • Partner news
    • Resources
      • MSP guides
      • Partner Care
      • Sophos Central
    • Webinars & Events
      • Webinars & Events
      • Calendar
    • Become a partner
      • Join our program
  • Events & Webinars
    • Events & Webinars
      • Events & Webinars
      • Calendar
      • Recordings
  • Getting Started
    • Getting started in the Community
      • How to get started
      • SophosID registration
      • How to set up your profile
      • How to contribute and participate
      • How to manage private messages
    • Member recognition
      • Recognition program
      • Leaderboard
  • Support Portal
Sophos Integrations
Sophos Integrations
Integrations Splunk Add on for Sophos Central
  • Release Notes & News
  • Integrations
  • Forums
  • Early Access Programs
  • Sophos MSP Program
  • Ideation
  • Members
  • More
  • Cancel
  • New
Sophos Integrations requires membership for participation - click to join
  • -Third Party Integrations
    • +ConnectWise Automate.
    • +Datto RMM
    • N-Able N-Central
    • +NinjaRMM
    • +Sophos integration with Kaseya VSA
    • -Splunk apps for Sophos
      • Splunk Add on for Sophos Central
      • Splunk Add on for Sophos Next-Gen Firewall
    • SynchroMSP
  • Central Partner - Customer CSV

Splunk Add on for Sophos Central

Installation

  • Install Splunk in your local machine
  • Download the Sophos Central Add-on from Splunkbase
  • Copy TA-sophos-central-addon-for-splunk directory to splunk/etc/apps/ directory
  • Restart Splunk.
  • After installing the Splunk, Switch to /splunk/bin directory
  • By following command user can generate SPL file :
    • MAC/Linux: ./splunk package app your_app_name (TA-sophos-central-addon-for-splunk)
    • Windows: splunk package app your_app_name (TA-sophos-central-addon-for-splunk)
  • User will get location of spl like this:
  • User can install add-on with this SPL file into Splunk

Authentication & Configuration

  • Authentication uses a Client ID and Secret pair from a Tenant or Enterprise admin account.
    • If using an enterprise admin account, this will authenticate to all managed tenants this account has permissions for
      • See here for instructions on Creating a service principal for an Enterprise Admin
      • See here for instructions onCreating a service principal for an for a Tenant
  • Once you have created your API Client ID and Secret pair from the instructions above
    • From within the Splunk interface, navigate to: Apps → Sophos Central Addon for Splunk → Configuration → Addon Settings
      • Enter the "Client ID" and "Client Secret" in the fields and press "Save"

  • Next navigate to the "Inputs" tab to configure settings for sync intervals, default indexes, and to enable or disable a specific input.
    • Recommended sync intervals are following
      • Tenants - Daily
      • Endpoints - Hourly
      • Alerts - Hourly
      • Events - Hourly

Note: Depending on the default sync times it may take up to 24 hours for the initial sync to occur and the data to display in your Splunk instance.

  • Once you have configured your initial sync settings, we recommend viewing the options for Events as you have additional configuration options to exclude specific event types as shown in the below example.

 

Help & Troubleshooting

Logs can be found on the Splunk server at: $SPLUNK_HOME/var/log/TA-sophos-central-addon-for-splunk/

For feedback and support please post to our Splunk forum or email: apis @ sophos.com

 

  • Share
  • History
  • More
  • Cancel

Defeat Cyberattacks

Footer - Default

  • Column 1
    • Endpoint Security
      • Sophos Endpoint
      • Sophos XDR
      • Device Encryption
      • Sophos Mobile
    • Email Security
      • Sophos Email
      • Phish Threat
    • Support Tools
      • Sophos integrations
      • Free tools
  • Column 2
    • Network Security
      • Sophos Firewall
      • Sophos ZTNA
      • Sophos Switch
      • UTM Firewall
      • Sophos Wireless
      • Sophos NDR
    • Cloud Security
      • Sophos Central
      • Sophos Cloud Optix
  • Column 3
    • Partners
      • Find a partner
      • Managed service providers
      • Join our program
    • Current Partners
      • Partners blog
      • Local Partner Community blog
      • Partner MSG guides
      • Partner news
      • Partner care
      • Partner portal login
      • Training & certification
    • Management Platform
      • Sophos Central
  • Column 4
    • Support
      • Downloads and updates
      • Support packages
      • Support portal
      • Sophos Customer Success
      • Sophos Techvids
      • Sophos Learning Center
      • Sophos status
      • Tech support
    • Learn
      • Threat intelligence
      • X-Ops threat research
      • Trust center
      • Security blogs
      • Sophos Academy
  • Column 5
    • Getting Started
      • How to get started
      • Community FAQs
    • Member Recognition
      • Recognition program
      • Leaderboard
    • Events & Webinars
      • Webinars
      • Calendar
      • Recordings
  • Column 6
    • Try for Free
      • Free trials
      • Product demos
    • Sophos Home Premium
      • Sophos Home support
      • Contact Home support
      • Mac antivirus download
      • PC antivirus download
    • About Us
      • Company
      • Events
      • Press
      • Careers
  • Getting Started
  • Terms
  • Privacy
    • Privacy Notice
    • Cookies
  • Legal
    • General
    • Modern Slavery Statement
    • Speak Out
© 1997- Sophos Ltd. All Rights Reserved.