Hello,
I have installed sysmon and I try to send it with a UniversalForwarder on that machine to my Splunk-Indexer and Search-Head...
I have tryed to add
[WinEventLog://Microsoft-Windows-Sysmon/Operational]
disabled = 0
[WinEventLog://"Applications and Services Logs/Microsoft/Windows/Sysmon/Operational"]
disabled = 0
[WinEventLog://Applications and Services Logs/Microsoft/Windows/Sysmon/Operational]
disabled = 0
to the inputs.conf, but non of that versions worked...
I have also restarted the UniversalForwarder and the Indexer / Search-Head has the Sysmom app installed.
What am I doing wong?!
PS.: Sysmon is running and I see the logged data in the Eventviewer of that machine...
I got the following errors in my Splunk Error Logs:
Failed to find Event Log with channel name=Applications and Services Logs/Microsoft/Windows/Sysmon/Operational
Init failed, unable to subscribe to Windows Event Log channel Microsoft-Windows-Sysmon/Operational: errorCode=5