hi experts
seek assistance with configuring Sysmon for inputs.conf on a Splunk Universal Forwarder.
Configuration based on the Splunk Technology Add-on (TA) for Sysmon.
[WinEventLog://Microsoft-Windows-Sysmon/Operational]
disabled = false
renderXml = 1
source = XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
index = sysmon
is this the correct config ?
The path looks good. Assuming your index=sysmon exists, it should bring in logs. Give it a shot and see if the logs come in.