All Apps and Add-ons

Bug Report - Add-on for Microsoft Sysmon v10.3.0

chris_barrett
SplunkTrust
SplunkTrust

The Add-on's props.conf has a REPORT statement that calls, among others, sysmon-dns-record-data and sysmon-dns-ip-data. But there are no stanzas by these names in the Add-on's transforms.conf There are however [extract_dns_record_data] and [extract_dns_ip_data]. I'm not sure if it's just a case of the names needing to be aligned.

0 Karma
Get Updates on the Splunk Community!

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...

New Articles from Academic Learning Partners, Help Expand Lantern’s Use Case Library, ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Your Guide to SPL2 at .conf24!

So, you’re headed to .conf24? You’re in for a good time. Las Vegas weather is just *chef’s kiss* beautiful in ...