icon/x Created with Sketch.

Splunk Cookie Policy

We use our own and third-party cookies to provide you with a great online experience. We also use these cookies to improve our products and services, support our marketing campaigns, and advertise to you on our website and other websites. Some cookies may continue to collect information after you have left our website. Learn more (including how to update your settings) here.
Accept Cookie Policy

We are working on something new...

A Fresh New Splunkbase
We are designing a New Splunkbase to improve search and discoverability of apps. Check out our new and improved features like Categories and Collections. New Splunkbase is currently in preview mode, as it is under active development. We welcome you to navigate New Splunkbase and give us feedback.

Accept License Agreements

This app is provided by a third party and your right to use the app is in accordance with the license provided by that third-party licensor. Splunk is not responsible for any third-party apps and does not provide any warranty or support. If you have any questions, complaints or claims with respect to this app, please contact the licensor directly.

Thank You

Downloading Sophos Central app for Splunk
SHA256 checksum (sophos-central-app-for-splunk_106.tgz) a53c974771bf1b7b35462851797bc9f48b9a3bf522e71c9d614f55b643d28516 SHA256 checksum (sophos-central-app-for-splunk_105.tgz) c394713f6f1a7c0e63f8995c84639711a7db84439c9862dc1a0caf345accbeb8 SHA256 checksum (sophos-central-app-for-splunk_102.tgz) e88a90383d949cd550be65ce3a7741cb2bd5c4e8d264ae502ef6aa56b272f60b SHA256 checksum (sophos-central-app-for-splunk_101.tgz) a6dd74bf6c3d8ef3453b13ddb69ec7b084478b4a534ba486e5cd9520235a933d
To install your download
For instructions specific to your download, click the Details tab after closing this window.

Flag As Inappropriate

splunk

Sophos Central app for Splunk

This app has been archived. Learn more about app archiving.
This app is NOT supported by Splunk. Please read about what that means for you here.
Overview
Details
This Splunk App leverages the Sophos Central API to collect events and alert notifications from registered endpoints and devices.

The application provides an overview dashboard and fields conforming to CIM 4.8 Malware_*

You will need to obtain an API key from your Sophos Central account. On first run the setup screen will prompt you to configure the app with your account details
See https://github.com/nickhills81/sophos_central/blob/master/README.md for details on obtaining your credentials.

About Sophos Central
Sophos Central is a web-hosted solution which offers protection for users across all their devices and for servers and is the tool that lets administrators manage protection, enforce policies, take action against threats, and generate reports.

Sophos Central App for Splunk

This Splunk App leverages the Sophos Central API to collect events and alert notifications from registered endpoints and devices.

The application provides an overview dashboard, and fields conforming to CIM 4.8 Malware_*

You will need to obtain an API key from your Sophos Central account. On first run the setup screen will prompt you to configure the app with your account details

*Icon made by Freepik from www.flaticon.com*

Configure the Application

You will need to obtain a Sophos Central API token to start reciving events from Sophos Central. To do so, login to your Sophos Central acocunt, and navigate to Global Settings, and then choose "API Token Management"

Choose "New Token" and then provide a name for the token.

From the resulting credentials you will need to make note of the "api access url", "x-api-key" and authorisation string.

Open the Splunk App, and enter the details as follows

Release Notes

Version 1.0.6
Aug. 1, 2018

Thank You For Using "Sophos Central App for Splunk"
Notice: This app should be considered depricated

Thank you for using this Splunk App, I hope you have found it useful and I thank the many of you who have offered words of thanks and contributed improvments and bug fixes.

In late 2017 I changed jobs which meant I no longer had access to a Sophos Central subcription which made updating and helping users a bit more challenging. Where possible I had tried to incorporate changes, but this was not always easy.

However...

From 1st August Sophos have released thier own supported TA and Application, and this should be the recommended approach for all existing Sophos users.
You can find the new Sophos Supported Versions here:
TA Sophos Add-on for Splunk https://splunkbase.splunk.com/app/4096/
APP Sophos App for Splunk https://splunkbase.splunk.com/app/4097/

Thanks once again. Happy Splunking!
Nick

Version 1.0.5
Oct. 15, 2017

Minor bug fixes as contributed from Splunk Answers - Thanks for the feedback!
Also - cross platform compatibility improved (windows)

Version 1.0.2
June 7, 2017
  • Fixed authentication bug
  • Corrected Typo

Please feedback suggestions and enhancements via Splunk Answers

Version 1.0.1
June 6, 2017

Initial release.
Please submit feedback via answers.splunk.com


Subscribe Share

Are you a developer?

As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps from Splunk, our partners and our community. Find an app for most any data source and user need, or simply create your own with help from our developer portal.

Follow Us:
Splunk, Splunk>,Turn Data Into Doing, Data-to-Everything, and D2E are trademarks or registered trademarks of Splunk Inc. in the United States and other countries. All other brand names,product names,or trademarks belong to their respective owners.