Splunk Enterprise

How to ingest exported sysmon logs to Splunk?


Hello Guys

I'm trying to ingest exported sysmon logs file to Splunk. I got the file from Splunk attack_data repository. I have already installed Microsoft sysmon add-ons.

Splunk attack_data's link: 


Every time when I choose xmlWinEventLog:Microsoft-Windows-Sysmon/Operational as a source type, it gives me error Not found.  appreciate your support, how can I ingest exported sysmon logs to splunk?


Thanks, Awni

Labels (1)
0 Karma


Did you ever find a solution for this? Looking at the below documentation it seems that this is not supported https://docs.splunk.com/Documentation/Splunk/9.1.2/Data/Uploaddata

0 Karma


On which Splunk instance(s) did you install the sysmon add-ons?

There is no link in the question.

What exactly are you trying to do when you choose xmlWinEventLog:Microsoft-Windows-Sysmon/Operational as a source type?  What are you choosing it from?  Which Splunk instance are you using at the time?

If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Get ready to show some Splunk Certification swagger at .conf24!

Dive into the deep end of data by earning a Splunk Certification at .conf24. We're enticing you again this ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Now On-Demand Join us to learn more about how you can leverage Service Level Objectives (SLOs) and the new ...

Database Performance Sidebar Panel Now on APM Database Query Performance & Service ...

We’ve streamlined the troubleshooting experience for database-related service issues by adding a database ...