Getting Data In

How to import sysmon logs to Splunk?

onurasln55
Explorer

I choose source from forwarded input selection to input in splunk. I can't see sysmon in logs from source. I made the inputs.conf setting via forwarder, unfortunately I couldn't see it again. I have logs. There are forwarders. My other logs are coming. The sysmon log is not coming.

I would appreciate your help.

forwarded event.png

 

not sysmon log 

not systmon.png 

inputconf.pngsysmon log.pnglog name.png

Labels (2)
Tags (1)
1 Solution

onurasln55
Explorer

I found a solution by editing the inputs.conf file as follows.

 

[WinEventLog://Microsoft-Windows-Sysmon/Operational]
disabled = false
renderXml = true
index= sysmon
source = XmlWinEventLog:Microsoft-Windows-Sysmon/Operational

View solution in original post

0 Karma

onurasln55
Explorer

I found a solution by editing the inputs.conf file as follows.

 

[WinEventLog://Microsoft-Windows-Sysmon/Operational]
disabled = false
renderXml = true
index= sysmon
source = XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
0 Karma

smurf
Communicator

Hi,

Did you check your default index? It would be main if you didn't change it.

smurf

0 Karma
Get Updates on the Splunk Community!

Database Performance Sidebar Panel Now on APM Database Query Performance & Service ...

We’ve streamlined the troubleshooting experience for database-related service issues by adding a database ...

IM Landing Page Filter - Now Available

We’ve added the capability for you to filter across the summary details on the main Infrastructure Monitoring ...

Dynamic Links from Alerts to IM Navigators - New in Observability Cloud

Splunk continues to improve the troubleshooting experience in Observability Cloud with this latest enhancement ...