Splunk Search

Heavy forwarder and sysmon

verifi81
Path Finder

Hello friends,

 

Suppose I install Microsoft Sysmon on a Windows server.  

I then go install the Universal Forwarder on the Windows server with the default settings.  A deployment server is in the mix too if that matters.  

My question is this.  Will the Universal Forwarder know to pick up the Syslog events if using all default settings? Is that defined on the Deployment server?

Labels (1)
0 Karma
1 Solution

venkatasri
SplunkTrust
SplunkTrust

Hi @verifi81 

By default add-on having sysmon events disabled you shall deploy it UF either via DeploymentServer (DS) having it enabled.  DS doesn't define anything it's the admin who supposed to enable it and put it on DS then whitelist the add-on to get deployed to UF that you wish to.

--

An upvote would be appreciated and Accept the solution if this reply helps!

View solution in original post

0 Karma

venkatasri
SplunkTrust
SplunkTrust

Hi @verifi81 

By default add-on having sysmon events disabled you shall deploy it UF either via DeploymentServer (DS) having it enabled.  DS doesn't define anything it's the admin who supposed to enable it and put it on DS then whitelist the add-on to get deployed to UF that you wish to.

--

An upvote would be appreciated and Accept the solution if this reply helps!

0 Karma

venkatasri
SplunkTrust
SplunkTrust

@verifi81 sysmon settings have been shared here FYI - Solved: Re: Connectivity issues - Splunk Community

--

An upvote would be appreciated if this reply helps!

0 Karma
Get Updates on the Splunk Community!

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...