Default Version 1.0.0
June 11, 2019
June 11, 2019
Splunk Enterprise
Platform Version: 9.4, 9.3, 9.2, 9.1, 9.0
CIM Version: 4.x
Log in to rate this app
This Add-on was designed to parse fields from Sophos XG firewall to CIM compliant fields for Network_Traffic, Intrusion_Detection, and Web data models. Onboard data as sourcetype=sophos:xg:syslog Data will sub-sourcetype to various sourcetypes such as sophos:xg:Firewall, sophos:xg:ContentFiltering, sophos:xg:IDP, etc.
Log in to report this app listing.