Anyone have any insight into why the MS sysmon addon was removed from the available apps on Splunk Cloud? I am teaching a class and I use Splunk with sysmon to demonstrate the importance of logging and investigations in computer forensics. I swear that it was there last year this time... Thanks!
Now supported!
Splunk Awesomeness Video’s related to using sysmon and Splunk core for some security use cases!
Splunking the Endpoint (video) by James Brodsky - http://conf.splunk.com/session/2015/recordings/2015-splunk-119.mp4
Best Practices for Scoping Infections and Disrupting Breaches - https://splunkevents.webex.com/ec3100/eventcenter/recording/recordAction.do?theAction=poprecord&AT=p...