<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Sysmon TA vs Splunk TA windows in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Sysmon-TA-vs-Splunk-TA-windows/m-p/565420#M100610</link>
    <description>&lt;P&gt;Hey,&lt;/P&gt;&lt;P&gt;We do have &lt;STRONG&gt;Sysmom&amp;nbsp;&lt;/STRONG&gt;installed on our Windows servers and workstations&lt;BR /&gt;&lt;BR /&gt;A quick description of what sysmon is from docs.microsoft.com (&lt;A title="Sysmon" href="https://docs.microsoft.com/en-us/sysinternals/downloads/sysmon" target="_blank" rel="noopener"&gt;link&lt;/A&gt;)&lt;BR /&gt;&lt;EM&gt;"sysmon is a Windows system service and device driver that, once installed on a system, remains resident across system reboots to monitor and log system activity to the Windows event log."&lt;BR /&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Since Sysmon itself does not offer as a product log analysis, we thought that sending the logs into Splunk would be the right solution here &lt;span class="lia-unicode-emoji" title=":smiling_face_with_smiling_eyes:"&gt;😊&lt;/span&gt;&lt;/P&gt;&lt;P&gt;* A disadvantage of this is the need to set up and maintain dozens of Splunk UF's on workstations....&lt;/P&gt;&lt;P&gt;&lt;FONT size="4"&gt;What application do I should install, If we already have deployed Splunk TA Windows?&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;We have found &lt;A href="https://splunkbase.splunk.com/app/3544/" target="_blank" rel="noopener"&gt;App&lt;/A&gt; &amp;amp; &lt;A href="https://splunkbase.splunk.com/app/1914/" target="_blank" rel="noopener"&gt;addon&lt;/A&gt; for sysmon in splunkbase. However, the data Sysmon generates is most of the time windows event logs and perfmon events, so the events would come into indexes generated by the&amp;nbsp;&lt;STRONG&gt;Splunk TA windows.&amp;nbsp;&lt;/STRONG&gt;We do not want the information being doubled and collected in both apps under different sourcetypes and indexes....&lt;BR /&gt;&lt;BR /&gt;Have anyone done this before? What's are your reccomendations?&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;/P&gt;&lt;P&gt;Tankwell&lt;/P&gt;</description>
    <pubDate>Wed, 01 Sep 2021 06:25:54 GMT</pubDate>
    <dc:creator>omershira</dc:creator>
    <dc:date>2021-09-01T06:25:54Z</dc:date>
    <item>
      <title>Sysmon TA vs Splunk TA windows</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sysmon-TA-vs-Splunk-TA-windows/m-p/565420#M100610</link>
      <description>&lt;P&gt;Hey,&lt;/P&gt;&lt;P&gt;We do have &lt;STRONG&gt;Sysmom&amp;nbsp;&lt;/STRONG&gt;installed on our Windows servers and workstations&lt;BR /&gt;&lt;BR /&gt;A quick description of what sysmon is from docs.microsoft.com (&lt;A title="Sysmon" href="https://docs.microsoft.com/en-us/sysinternals/downloads/sysmon" target="_blank" rel="noopener"&gt;link&lt;/A&gt;)&lt;BR /&gt;&lt;EM&gt;"sysmon is a Windows system service and device driver that, once installed on a system, remains resident across system reboots to monitor and log system activity to the Windows event log."&lt;BR /&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Since Sysmon itself does not offer as a product log analysis, we thought that sending the logs into Splunk would be the right solution here &lt;span class="lia-unicode-emoji" title=":smiling_face_with_smiling_eyes:"&gt;😊&lt;/span&gt;&lt;/P&gt;&lt;P&gt;* A disadvantage of this is the need to set up and maintain dozens of Splunk UF's on workstations....&lt;/P&gt;&lt;P&gt;&lt;FONT size="4"&gt;What application do I should install, If we already have deployed Splunk TA Windows?&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;We have found &lt;A href="https://splunkbase.splunk.com/app/3544/" target="_blank" rel="noopener"&gt;App&lt;/A&gt; &amp;amp; &lt;A href="https://splunkbase.splunk.com/app/1914/" target="_blank" rel="noopener"&gt;addon&lt;/A&gt; for sysmon in splunkbase. However, the data Sysmon generates is most of the time windows event logs and perfmon events, so the events would come into indexes generated by the&amp;nbsp;&lt;STRONG&gt;Splunk TA windows.&amp;nbsp;&lt;/STRONG&gt;We do not want the information being doubled and collected in both apps under different sourcetypes and indexes....&lt;BR /&gt;&lt;BR /&gt;Have anyone done this before? What's are your reccomendations?&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;/P&gt;&lt;P&gt;Tankwell&lt;/P&gt;</description>
      <pubDate>Wed, 01 Sep 2021 06:25:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sysmon-TA-vs-Splunk-TA-windows/m-p/565420#M100610</guid>
      <dc:creator>omershira</dc:creator>
      <dc:date>2021-09-01T06:25:54Z</dc:date>
    </item>
  </channel>
</rss>

