Lookups for the Splunk Add-on for Sysmon for Linux
The Splunk Add-on for Sysmon for Linux has the following lookups that map fields from Sysmon to Common Information Model (CIM)-compliant values in the Splunk software. The lookup files are located in $SPLUNK_HOME\etc\apps\Splunk_TA_sysmon-for-linux/lookups
Filename | Description |
---|---|
sysmon_for_linux_eventid.csv | Maps EventID to EventDescription. For more information, see the Sysmon For Linux documentation. |
Source types for the Splunk Add-on for Sysmon for Linux | Release notes for the Splunk Add-on for Sysmon For Linux |
This documentation applies to the following versions of Splunk® Supported Add-ons: released
Feedback submitted, thanks!