<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Heavy forwarder and sysmon in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Heavy-forwarder-and-sysmon/m-p/560731#M159376</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/222747"&gt;@verifi81&lt;/a&gt;&amp;nbsp;sysmon settings have been shared here FYI -&amp;nbsp;&lt;A href="https://community.splunk.com/t5/Getting-Data-In/Connectivity-issues/m-p/560318/highlight/true#M92616" target="_blank"&gt;Solved: Re: Connectivity issues - Splunk Community&lt;/A&gt;&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;An upvote would be appreciated if this reply helps!&lt;/P&gt;</description>
    <pubDate>Mon, 26 Jul 2021 04:44:38 GMT</pubDate>
    <dc:creator>venkatasri</dc:creator>
    <dc:date>2021-07-26T04:44:38Z</dc:date>
    <item>
      <title>Heavy forwarder and sysmon</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Heavy-forwarder-and-sysmon/m-p/560729#M159374</link>
      <description>&lt;P&gt;Hello friends,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Suppose I install Microsoft Sysmon on a Windows server.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I then go install the Universal Forwarder on the Windows server with the default settings.&amp;nbsp; A deployment server is in the mix too if that matters.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My question is this.&amp;nbsp; Will the Universal Forwarder know to pick up the Syslog events if using all default settings? Is that defined on the Deployment server?&lt;/P&gt;</description>
      <pubDate>Mon, 26 Jul 2021 04:23:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Heavy-forwarder-and-sysmon/m-p/560729#M159374</guid>
      <dc:creator>verifi81</dc:creator>
      <dc:date>2021-07-26T04:23:46Z</dc:date>
    </item>
    <item>
      <title>Re: Heavy forwarder and sysmon</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Heavy-forwarder-and-sysmon/m-p/560730#M159375</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/222747"&gt;@verifi81&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;By default add-on having sysmon events disabled you shall deploy it UF either via DeploymentServer (DS) having it enabled.&amp;nbsp; DS doesn't define anything it's the admin who supposed to enable it and put it on DS then whitelist the add-on to get deployed to UF that you wish to.&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;An upvote would be appreciated and Accept the solution if this reply helps!&lt;/P&gt;</description>
      <pubDate>Mon, 26 Jul 2021 04:39:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Heavy-forwarder-and-sysmon/m-p/560730#M159375</guid>
      <dc:creator>venkatasri</dc:creator>
      <dc:date>2021-07-26T04:39:09Z</dc:date>
    </item>
    <item>
      <title>Re: Heavy forwarder and sysmon</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Heavy-forwarder-and-sysmon/m-p/560731#M159376</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/222747"&gt;@verifi81&lt;/a&gt;&amp;nbsp;sysmon settings have been shared here FYI -&amp;nbsp;&lt;A href="https://community.splunk.com/t5/Getting-Data-In/Connectivity-issues/m-p/560318/highlight/true#M92616" target="_blank"&gt;Solved: Re: Connectivity issues - Splunk Community&lt;/A&gt;&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;An upvote would be appreciated if this reply helps!&lt;/P&gt;</description>
      <pubDate>Mon, 26 Jul 2021 04:44:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Heavy-forwarder-and-sysmon/m-p/560731#M159376</guid>
      <dc:creator>venkatasri</dc:creator>
      <dc:date>2021-07-26T04:44:38Z</dc:date>
    </item>
  </channel>
</rss>

