- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
VijaySrrie
Builder
07-11-2021
06:04 PM
Hi,
For "Endpoint datamodel" with specific to "sysmon" sourcetype, what are all the mandatory fields?
1 Solution
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
venkatasri

SplunkTrust
07-11-2021
06:31 PM
Hi @VijaySrrie
Splunk Add-On for Microsoft Sysmon | Splunkbase Add-on having CIM mapping for sysmon data, you can find out the extractions by downloading it.
---
An upvote would be appreciated and Accept solution if it helps!
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
venkatasri

SplunkTrust
07-11-2021
06:31 PM
Hi @VijaySrrie
Splunk Add-On for Microsoft Sysmon | Splunkbase Add-on having CIM mapping for sysmon data, you can find out the extractions by downloading it.
---
An upvote would be appreciated and Accept solution if it helps!
