All Apps and Add-ons

Bug Report - Add-on for Microsoft Sysmon v10.3.0


The Add-on's props.conf has a REPORT statement that calls, among others, sysmon-dns-record-data and sysmon-dns-ip-data. But there are no stanzas by these names in the Add-on's transforms.conf There are however [extract_dns_record_data] and [extract_dns_ip_data]. I'm not sure if it's just a case of the names needing to be aligned.

0 Karma
Get Updates on the Splunk Community!

Index This | A sphere has three, a circle has two, and a point has zero. What is it?

September 2023 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

Build Scalable Security While Moving to Cloud - Guide From Clayton Homes

 Clayton Homes faced the increased challenge of strengthening their security posture as they went through ...

Mission Control | Explore the latest release of Splunk Mission Control (2.3)

We’re happy to announce the release of Mission Control 2.3 which includes several new and exciting features ...