The Splunk Add-on for Sophos allows a Splunk® Enterprise administrator to collect Sophos Endpoint Security events and map them to the Splunk CIM. You can then use the data with other Splunk apps, such as the Splunk App for Enterprise Security and the Splunk App for PCI Compliance. This add-on must be installed on a Windows instance of Splunk Enterprise for data collection. The add-on is platform independent for indexers and search heads.
(0)
Categories
Created By
Type
Downloads
Licensing
Splunk Answers
Resources