Skip to main content
Warning
This app is archived. App archiving documentation
Splunk Add-on for Sophos app icon

Splunk Add-on for Sophos

The Splunk Add-on for Sophos allows a Splunk® Enterprise administrator to collect Sophos Endpoint Security events and map them to the Splunk CIM. You can then use the data with other Splunk apps, such as the Splunk App for Enterprise Security and the Splunk App for PCI Compliance.Built by Splunk LLC
splunk product badge

Default Version 3.4.0

November 11, 2020

Compatibility

Splunk Enterprise

Platform Version: 10.5, 10.4, 10.3, 10.2, 10.1, 10.0, 9.4, 9.3, 9.2, 9.1, 9.0

CIM Version: 4.x

Rating
3
(7)

Log in to rate this app

Support
Archived Add-on
Ranking

#45 in Utilities

The Splunk Add-on for Sophos allows a Splunk® Enterprise administrator to collect Sophos Endpoint Security events and map them to the Splunk CIM. You can then use the data with other Splunk apps, such as the Splunk App for Enterprise Security and the Splunk App for PCI Compliance. This add-on must be installed on a Windows instance of Splunk Enterprise for data collection. The add-on is platform independent for indexers and search heads.