All Apps and Add-ons

Where to install apps on the the client side ?

gargantua
Path Finder

Dear Splunkers,

I just set up a little testing environment, with Splunk Enterprise running smoothly on a Debian server and a Universal Forwarder running on a Windows 10 machine.

My goal is to send some sysmon logs into Splunk.

I first started to follow this page from the official Splunk documentation : https://docs.splunk.com/Documentation/AddOns/released/MSSysmon/Install

But unfortunately, this page does not explain how to install the client side of the app (is there a client side anyway ? Well nothing is explained about it).

What I did is that I set my inputs.conf file in etc/system/local on the client machine.

It partially worked, as the data is being sent to the Splunk server, but none of the fancy dashboards and graphs that the Sysmon for Splunk add-on or app is supposed to display is available.

I know I must have missed something on the client part, but I also have to mention here that the kafkaesque intricated tons-of-links Splunk documentation does not help me much, to say the least.

It would be extremely nice if someone could turn on the light because so far, my Splunk journey is being black as midnight in a moonless night.

Thanks a lot 🙂
Gargantua

Labels (1)
0 Karma

PaulPanther
Motivator

The client side setup is described on Configure inputs for the Splunk Add-on for Sysmon - Splunk Documentation

The mentioned Add-on does not provide any dashboards. I assume that you're using that Sysmon App for Splunk | Splunkbase , right?

If yes you have to modify search macros as described under Details Tab.

A macro is used for all saved searches, you will need to modify it for your environment to ensure the proper Sysmon sourcetype/index is searched.

Macros: Settings --> Advanced Search --> Search Macros. Edit to your environment

Default - sourcetype="XmlWinEventLog:Microsoft-Windows-Sysmon/Operational"

Thats it.

  

Get Updates on the Splunk Community!

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...