Splunk Enterprise Security

Endpoint datamodel

VijaySrrie
Builder

Hi,

For "Endpoint datamodel" with specific to "sysmon" sourcetype, what are all the mandatory fields?

 

 

Labels (1)
0 Karma
1 Solution

venkatasri
SplunkTrust
SplunkTrust

Hi @VijaySrrie 

Splunk Add-On for Microsoft Sysmon | Splunkbase Add-on having CIM mapping for sysmon data, you can find out the extractions by downloading it.

---

An upvote would be appreciated and Accept solution if it helps!

View solution in original post

0 Karma

venkatasri
SplunkTrust
SplunkTrust

Hi @VijaySrrie 

Splunk Add-On for Microsoft Sysmon | Splunkbase Add-on having CIM mapping for sysmon data, you can find out the extractions by downloading it.

---

An upvote would be appreciated and Accept solution if it helps!

0 Karma
Get Updates on the Splunk Community!

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to Officially Supported Splunk ...