Default Version 1.0.4
February 8, 2022
February 8, 2022
Splunk Enterprise
Platform Version: 9.4, 9.3, 9.2, 9.1, 9.0
CIM Version: 4.x
Log in to rate this app
The Splunk Add-on for Linux Sysmon extract fields from syslog data. Add-On map events for CIM data models: Endpoint, Network Resolution (DNS), Network Traffic, Change. The Splunk Add-on for Linux Sysmon provides the parsing and CIM-compatible knowledge to use with other Splunk apps, such as Splunk Enterprise Security and the Splunk App for PCI Compliance.
Log in to report this app listing.