Hi,
For "Endpoint datamodel" with specific to "sysmon" sourcetype, what are all the mandatory fields?
Hi @VijaySrrie
Splunk Add-On for Microsoft Sysmon | Splunkbase Add-on having CIM mapping for sysmon data, you can find out the extractions by downloading it.
---
An upvote would be appreciated and Accept solution if it helps!
Hi @VijaySrrie
Splunk Add-On for Microsoft Sysmon | Splunkbase Add-on having CIM mapping for sysmon data, you can find out the extractions by downloading it.
---
An upvote would be appreciated and Accept solution if it helps!