Hello,
After deploying the Splunk Universal Forwarder on a Windows machine, I am observing repeated process creation alerts being triggered by my security monitoring solution. These alerts are specifically related to the following Splunk processes:
These processes are essential for log collection and monitoring, but the constant alerts are causing noise in our monitoring system.
I would appreciate any advice or recommended best practices to handle this issue. Specifically:
Usually people safelist the SplunkForwarder service and the entire SplunkForwarder directory. You could safelist individual services and apps but you may end up spending lots of time playing whack-a-mole.
You may be able to look through the community forums and Splunk Slack usergroup for your particular EDR solution to see if others have specific tips applying to that EDR.