Skip to main content
Warning
This app is archived. App archiving documentation
Sophos XG Technical Add-on app icon

Sophos XG Technical Add-on

This Add-on was designed to parse fields from Sophos XG firewall to CIM compliant fields for Network_Traffic, Intrusion_Detection, and Web data models.Built by Brian Daniel Potter
splunk product badge

Default Version 1.0.0

June 11, 2019

Compatibility

Splunk Enterprise

Platform Version: 9.4, 9.3, 9.2, 9.1, 9.0

CIM Version: 4.x

Rating
1
(1)

Log in to rate this app

Support
Archived Add-on

This Add-on was designed to parse fields from Sophos XG firewall to CIM compliant fields for Network_Traffic, Intrusion_Detection, and Web data models. Onboard data as sourcetype=sophos:xg:syslog Data will sub-sourcetype to various sourcetypes such as sophos:xg:Firewall, sophos:xg:ContentFiltering, sophos:xg:IDP, etc.