Skip to main content
Sophos Email Security Add-on app icon

Sophos Email Security Add-on

Collects Sophos Email message events (accepted, processed, quarantined, delivered and more) from the Sophos Central XDR Data LakeBuilt by Crossrealms, Inc. - Partner, an official Splunk Partner
splunk product badge

Default Version 1.0.0

October 6, 2026

Compatibility

Splunk Enterprise, Splunk Cloud

Platform Version: 10.6, 10.5, 10.4, 10.3, 10.2, 10.1, 10.0, 9.4, 9.3, 9.2

CIM Version: 8.x, 6.x, 5.x, 4.x

Rating
0
(0)

Log in to rate this app

Support
Developer Supported

The Splunk Add-on for Sophos Email Security collects Sophos Email message events (accepted, processed, quarantined, delivered and more) from the Sophos Central XDR Data Lake and maps them to the Splunk CIM Email data model. It supports Sophos Central tenant, partner and organization API credentials with automatic data region detection.