Revised Splunk App for Sophos Central Endpoint
Pre-Requisites:
- Splunk Enterprise 8.x : https://www.splunk.com/en_us/download/splunk-enterprise.html 1a. Not tested in Splunk Cloud, but app should be able to be uploaded as a "custom app"
- Sophos API Key: https://support.sophos.com/support/s/article/KB-000036372?language=en_US
- Create a new index "sophos" as set up the maximum size to 10GB or greater
- Install and install Sophos Central Add-on: https://splunkbase.splunk.com/app/4647/
- Download and configure Sophos Central Python Scripts: https://github.com/sophos/Sophos-Central-SIEM-Integration
Installation:
- Log into Splunk Enteprise
- Apps->Manage Apps->Install App from File