<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Sysmon App and Add-on installation failure in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Sysmon-App-and-Add-on-installation-failure/m-p/506319#M86214</link>
    <description>&lt;P&gt;I wanted to install &lt;STRONG&gt;Sysmon App for Splunk&lt;/STRONG&gt;&amp;nbsp;(App) and Microsoft &lt;STRONG&gt;Sysmon Add-on&lt;/STRONG&gt;&amp;nbsp;(Add-on) on my development server (Splunk 8.0.4.1).&amp;nbsp; I am running my development server on Ubuntu 18.04.4 LTS.&lt;/P&gt;&lt;P&gt;I thought it would be as easy as installing them both and looking at the&amp;nbsp;&lt;STRONG&gt;Sysmon App for Splunk&amp;nbsp;&lt;/STRONG&gt;I would get no events when I submitted to see the last 24 hours. I noticed that I was getting events in Search, but none were making it to the App.&amp;nbsp; I was getting an error for field extractions that said&lt;/P&gt;&lt;P&gt;Splunk could not perform action for resource data/props/extractions (404, 'Splunk cannot find "data/props/extractions/source::XmlWinEventLog:Microsoft-Windows-Sysmon//Operational : REPORT-sysmon". [HTTP 404] &lt;A href="https://127.0.0.1:8089/servicesNS/nobody/TA-microsoft-sysmon/data/props/extractions/source%253A%253AXmlWinEventLog%253AMicrosoft-Windows-Sysmon%252F%252FOperational%20%3A%20REPORT-sysmon?safe_encoding=1" target="_blank" rel="noopener"&gt;https://127.0.0.1:8089/servicesNS/nobody/TA-microsoft-sysmon/data/props/extractions/source%253A%253AXmlWinEventLog%253AMicrosoft-Windows-Sysmon%252F%252FOperational%20%3A%20REPORT-sysmon?safe_encoding=1&lt;/A&gt;; [{\'type\': \'ERROR\', \'code\': None, \'text\': \'Could not find object id=source%3A%3AXmlWinEventLog%3AMicrosoft-Windows-Sysmon//Operational : REPORT-sysmon\'}]')&lt;/P&gt;&lt;P&gt;I removed both the App and the Add-on, and started again.&amp;nbsp; It looked like the App did not require the Add-on, so I only installed the app.&amp;nbsp; I could then see several thousand sysmon messages in the App (Overview), but it did not look like any of the other tabs or panels were populating.&amp;nbsp; I also noticed that I "though" an XMLWinEventLog Source had appeared (before it was just the WinEventLogs that references sysmon.&lt;/P&gt;&lt;P&gt;I installed the Add-on, and then the app stopped displaying the sysmon messages in the overview total panel. I then removed the Add-on, and I can now see the Event Count and Event Count Over Time (in the Sysmon Overview), but none of the other tabs (Network Activity, Process Activity, etc) are populating.&lt;/P&gt;&lt;P&gt;I have 34,000 events in the&amp;nbsp;source="WinEventLog:Microsoft-Windows-Sysmon/Operational" query.&lt;/P&gt;&lt;P&gt;I have 670 events in the&amp;nbsp;source="XmlWinEventLog:Microsoft-Windows-Sysmon/Operational" query over the same time period (last 24 hours).&lt;/P&gt;&lt;P&gt;In a somewhat desperate attempt I read through the Security Essentials docs on configuring Sysmon, and they recommended deploying the Add-on to the UF (on the windows box running sysmon).&lt;/P&gt;&lt;P&gt;I did configure and check that I was getting a LOT of events with sysmon.&amp;nbsp; I had used the information from SwiftonSecurity (&lt;A href="https://github.com/SwiftOnSecurity/sysmon-config" target="_blank" rel="noopener"&gt;https://github.com/SwiftOnSecurity/sysmon-config&lt;/A&gt;) to configure Sysmon on my test workstation.&lt;/P&gt;&lt;P&gt;My ultimate goal was to send sysmon information to Security Essentials so I could use that to detect suspicious activity.&amp;nbsp; With the add-on removed there are very few fields in either the XmlEventLogs or the WinEventLogs data sources.&amp;nbsp; I would love to have a direction to move forw&lt;/P&gt;</description>
    <pubDate>Fri, 26 Jun 2020 16:05:36 GMT</pubDate>
    <dc:creator>state_larson_ti</dc:creator>
    <dc:date>2020-06-26T16:05:36Z</dc:date>
    <item>
      <title>Sysmon App and Add-on installation failure</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sysmon-App-and-Add-on-installation-failure/m-p/506319#M86214</link>
      <description>&lt;P&gt;I wanted to install &lt;STRONG&gt;Sysmon App for Splunk&lt;/STRONG&gt;&amp;nbsp;(App) and Microsoft &lt;STRONG&gt;Sysmon Add-on&lt;/STRONG&gt;&amp;nbsp;(Add-on) on my development server (Splunk 8.0.4.1).&amp;nbsp; I am running my development server on Ubuntu 18.04.4 LTS.&lt;/P&gt;&lt;P&gt;I thought it would be as easy as installing them both and looking at the&amp;nbsp;&lt;STRONG&gt;Sysmon App for Splunk&amp;nbsp;&lt;/STRONG&gt;I would get no events when I submitted to see the last 24 hours. I noticed that I was getting events in Search, but none were making it to the App.&amp;nbsp; I was getting an error for field extractions that said&lt;/P&gt;&lt;P&gt;Splunk could not perform action for resource data/props/extractions (404, 'Splunk cannot find "data/props/extractions/source::XmlWinEventLog:Microsoft-Windows-Sysmon//Operational : REPORT-sysmon". [HTTP 404] &lt;A href="https://127.0.0.1:8089/servicesNS/nobody/TA-microsoft-sysmon/data/props/extractions/source%253A%253AXmlWinEventLog%253AMicrosoft-Windows-Sysmon%252F%252FOperational%20%3A%20REPORT-sysmon?safe_encoding=1" target="_blank" rel="noopener"&gt;https://127.0.0.1:8089/servicesNS/nobody/TA-microsoft-sysmon/data/props/extractions/source%253A%253AXmlWinEventLog%253AMicrosoft-Windows-Sysmon%252F%252FOperational%20%3A%20REPORT-sysmon?safe_encoding=1&lt;/A&gt;; [{\'type\': \'ERROR\', \'code\': None, \'text\': \'Could not find object id=source%3A%3AXmlWinEventLog%3AMicrosoft-Windows-Sysmon//Operational : REPORT-sysmon\'}]')&lt;/P&gt;&lt;P&gt;I removed both the App and the Add-on, and started again.&amp;nbsp; It looked like the App did not require the Add-on, so I only installed the app.&amp;nbsp; I could then see several thousand sysmon messages in the App (Overview), but it did not look like any of the other tabs or panels were populating.&amp;nbsp; I also noticed that I "though" an XMLWinEventLog Source had appeared (before it was just the WinEventLogs that references sysmon.&lt;/P&gt;&lt;P&gt;I installed the Add-on, and then the app stopped displaying the sysmon messages in the overview total panel. I then removed the Add-on, and I can now see the Event Count and Event Count Over Time (in the Sysmon Overview), but none of the other tabs (Network Activity, Process Activity, etc) are populating.&lt;/P&gt;&lt;P&gt;I have 34,000 events in the&amp;nbsp;source="WinEventLog:Microsoft-Windows-Sysmon/Operational" query.&lt;/P&gt;&lt;P&gt;I have 670 events in the&amp;nbsp;source="XmlWinEventLog:Microsoft-Windows-Sysmon/Operational" query over the same time period (last 24 hours).&lt;/P&gt;&lt;P&gt;In a somewhat desperate attempt I read through the Security Essentials docs on configuring Sysmon, and they recommended deploying the Add-on to the UF (on the windows box running sysmon).&lt;/P&gt;&lt;P&gt;I did configure and check that I was getting a LOT of events with sysmon.&amp;nbsp; I had used the information from SwiftonSecurity (&lt;A href="https://github.com/SwiftOnSecurity/sysmon-config" target="_blank" rel="noopener"&gt;https://github.com/SwiftOnSecurity/sysmon-config&lt;/A&gt;) to configure Sysmon on my test workstation.&lt;/P&gt;&lt;P&gt;My ultimate goal was to send sysmon information to Security Essentials so I could use that to detect suspicious activity.&amp;nbsp; With the add-on removed there are very few fields in either the XmlEventLogs or the WinEventLogs data sources.&amp;nbsp; I would love to have a direction to move forw&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jun 2020 16:05:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sysmon-App-and-Add-on-installation-failure/m-p/506319#M86214</guid>
      <dc:creator>state_larson_ti</dc:creator>
      <dc:date>2020-06-26T16:05:36Z</dc:date>
    </item>
  </channel>
</rss>

