Release notes for the Splunk Add-on for Sysmon For Linux
Version 1.0.0 of the Splunk Add-on for Sysmon For Linux was released on October 24, 2022.
Compatibility
Version 1.0.0 of the Splunk Add-on for Sysmon for Linux is compatible with the following software, CIM versions, and platforms:
Splunk platform versions | 8.1, 8.2 and later |
CIM | 5.0 and later |
Supported OS for data collection | Platform independent |
Vendor products | Sysmon For Linux v1.0.2 |
New features
Sysmon for Linux events are available in /var/log/syslog and journald. The same events are logged in both locations so if you monitor any of those already, you should be aware of potential duplicates if both locations are monitored. The Add-on defines Sysmon For Linux events collection from journald and filters out non-sysmon events.
Fixed issues
There are no fixed issues for this release.
Known issues
Version 1.0.0 of the Splunk Add-on for Sysmon has the following, if any, known issues.
Third-party software attributions
Version 1.0.0 of the Splunk Add-on for Sysmon for Linux does not use third-party software or libraries.
Lookups for the Splunk Add-on for Sysmon for Linux | Release history |
This documentation applies to the following versions of Splunk® Supported Add-ons: released
Feedback submitted, thanks!