Configure your Sysmon for Linux deployment to collect data
Sysmon events are stored in Linux journald
Prepare your Sysmon configuration file based on your security team or SOC needs. You can start from attack_range/config. This is verbose, so adjust the filtering rules of each event type according to your environment needs.
To learn more about configuration file preparation and adjustment, see:
Installation and configuration overview for the Splunk Add-on for Sysmon For Linux | Install the Splunk Add-on for Sysmon For Linux |
This documentation applies to the following versions of Splunk® Supported Add-ons: released
Feedback submitted, thanks!