Splunk Enterprise Security

Endpoint datamodel

VijaySrrie
Builder

Hi,

For "Endpoint datamodel" with specific to "sysmon" sourcetype, what are all the mandatory fields?

 

 

Labels (1)
0 Karma
1 Solution

venkatasri
SplunkTrust
SplunkTrust

Hi @VijaySrrie 

Splunk Add-On for Microsoft Sysmon | Splunkbase Add-on having CIM mapping for sysmon data, you can find out the extractions by downloading it.

---

An upvote would be appreciated and Accept solution if it helps!

View solution in original post

0 Karma

venkatasri
SplunkTrust
SplunkTrust

Hi @VijaySrrie 

Splunk Add-On for Microsoft Sysmon | Splunkbase Add-on having CIM mapping for sysmon data, you can find out the extractions by downloading it.

---

An upvote would be appreciated and Accept solution if it helps!

0 Karma
Get Updates on the Splunk Community!

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...

State of Splunk Careers 2024: Maximizing Career Outcomes and the Continued Value of ...

For the past four years, Splunk has partnered with Enterprise Strategy Group to conduct a survey that gauges ...

Data-Driven Success: Splunk & Financial Services

Splunk streamlines the process of extracting insights from large volumes of data. In this fast-paced world, ...