Getting Data In

Sysmon TA vs Splunk TA windows

omershira
Explorer

Hey,

We do have Sysmom installed on our Windows servers and workstations

A quick description of what sysmon is from docs.microsoft.com (link)
"sysmon is a Windows system service and device driver that, once installed on a system, remains resident across system reboots to monitor and log system activity to the Windows event log."

 

Since Sysmon itself does not offer as a product log analysis, we thought that sending the logs into Splunk would be the right solution here 😊

* A disadvantage of this is the need to set up and maintain dozens of Splunk UF's on workstations....

What application do I should install, If we already have deployed Splunk TA Windows?

We have found App & addon for sysmon in splunkbase. However, the data Sysmon generates is most of the time windows event logs and perfmon events, so the events would come into indexes generated by the Splunk TA windows. We do not want the information being doubled and collected in both apps under different sourcetypes and indexes....

Have anyone done this before? What's are your reccomendations?

Regards,

Tankwell

Labels (2)
Tags (1)
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Index This | What travels the world but is also stuck in place?

April 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Discover New Use Cases: Unlock Greater Value from Your Existing Splunk Data

Realizing the full potential of your Splunk investment requires more than just understanding current usage; it ...

Continue Your Journey: Join Session 2 of the Data Management and Federation Bootcamp ...

As data volumes continue to grow and environments become more distributed, managing and optimizing data ...