Installation

Guidance Needed on Sysmon Configuration for inputs.conf in Universal Forwarder

siuolkl
Explorer

hi experts

seek assistance with configuring Sysmon for inputs.conf on a Splunk Universal Forwarder.

Configuration based on the Splunk Technology Add-on (TA) for Sysmon.

[WinEventLog://Microsoft-Windows-Sysmon/Operational]
disabled = false
renderXml = 1
source = XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
index = sysmon


is this the correct config ?

Labels (1)
0 Karma

marnall
Motivator

The path looks good. Assuming your index=sysmon exists, it should bring in logs. Give it a shot and see if the logs come in.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...