Troubleshoot the Splunk Add-on for Sysmon For Linux
For troubleshooting tips that you can apply to all add-ons, see Troubleshoot add-ons in Splunk Add-ons. For additional resources, see Support and resource links for add-ons in Splunk Add-ons.
Events fail to show
If events fail to show after disabling input for the Add-on for Linux Sysmon. Go to the instance where add-on is installed and run:
setfacl -n -m u:splunk:r /var/log/journal/*/system.journal
If events still show under "sysmon_linux" sourcetype, go to Settings > Data inputs > Systemd Journald Input for Splunk > sysmon and change the sourcetype to "sysmon:linux".
Migrate from Add-on for Linux Sysmon to the Splunk Add-on for Sysmon for Linux | Sysmon product comparisons |
This documentation applies to the following versions of Splunk® Supported Add-ons: released
Feedback submitted, thanks!