Configure inputs for the Splunk Add-on for Sysmon for Linux
The Splunk Add-on for Sysmon for Linux contains journald://sysmon input, which is enabled by default.
For more information, see https://docs.splunk.com/Documentation/Splunk/latest/Admin/Inputsconf.
Install the Splunk Add-on for Sysmon For Linux | Migrate from Add-on for Linux Sysmon to the Splunk Add-on for Sysmon for Linux |
This documentation applies to the following versions of Splunk® Supported Add-ons: released
Feedback submitted, thanks!