Default Version 1.0.0
October 6, 2026
October 6, 2026
Splunk Enterprise, Splunk Cloud
Platform Version: 10.6, 10.5, 10.4, 10.3, 10.2, 10.1, 10.0, 9.4, 9.3, 9.2
CIM Version: 8.x, 6.x, 5.x, 4.x
Log in to rate this app
The Splunk Add-on for Sophos Email Security collects Sophos Email message events (accepted, processed, quarantined, delivered and more) from the Sophos Central XDR Data Lake and maps them to the Splunk CIM Email data model. It supports Sophos Central tenant, partner and organization API credentials with automatic data region detection.
Log in to report this app listing.