All Apps and Add-ons

Where to install apps on the the client side ?

gargantua
Loves-to-Learn Everything

Dear Splunkers,

I just set up a little testing environment, with Splunk Enterprise running smoothly on a Debian server and a Universal Forwarder running on a Windows 10 machine.

My goal is to send some sysmon logs into Splunk.

I first started to follow this page from the official Splunk documentation : https://docs.splunk.com/Documentation/AddOns/released/MSSysmon/Install

But unfortunately, this page does not explain how to install the client side of the app (is there a client side anyway ? Well nothing is explained about it).

What I did is that I set my inputs.conf file in etc/system/local on the client machine.

It partially worked, as the data is being sent to the Splunk server, but none of the fancy dashboards and graphs that the Sysmon for Splunk add-on or app is supposed to display is available.

I know I must have missed something on the client part, but I also have to mention here that the kafkaesque intricated tons-of-links Splunk documentation does not help me much, to say the least.

It would be extremely nice if someone could turn on the light because so far, my Splunk journey is being black as midnight in a moonless night.

Thanks a lot 🙂
Gargantua

Labels (1)
0 Karma

PaulPanther
Builder

The client side setup is described on Configure inputs for the Splunk Add-on for Sysmon - Splunk Documentation

The mentioned Add-on does not provide any dashboards. I assume that you're using that Sysmon App for Splunk | Splunkbase , right?

If yes you have to modify search macros as described under Details Tab.

A macro is used for all saved searches, you will need to modify it for your environment to ensure the proper Sysmon sourcetype/index is searched.

Macros: Settings --> Advanced Search --> Search Macros. Edit to your environment

Default - sourcetype="XmlWinEventLog:Microsoft-Windows-Sysmon/Operational"

Thats it.

  

Get Updates on the Splunk Community!

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...