I found that I could add
protocol = tcp;udp
to the inbound and outbound WinNetMon stanzas in inputs.conf file on the UF. That stopped the ICMP traffic, which helps.
... View more
I found that I could add
protocol = tcp;udp
to the inbound and outbound WinNetMon stanzas in inputs.conf file on the UF. That stopped the ICMP traffic, which helps.
... View more
I'm wrestling with this as well. The WinNetMon traffic generates the largest number of events. Is there a way to write a RegEx to exclude processes, like ICMP which generates a lot of traffic?
... View more
Does this break when you render your events in XML format? That seems to have happened to me. Any thoughts on how to fix it, besides changing back?
... View more
I am trying to figure this out too. Can someone provide some examples from the inputs.conf file?
Using multikv mode seems to break the Splunk Microsoft Windows App. for network monitoring.
... View more