Note: Depending on the default sync times it may take up to 24 hours for the initial sync to occur and the data to display in your Splunk instance.
Logs can be found on the Splunk server at: $SPLUNK_HOME/var/log/TA-sophos-central-addon-for-splunk/
For feedback and support please post to our Splunk forum or email: apis @ sophos.com