Migrate from Add-on for Linux Sysmon to the Splunk Add-on for Sysmon for Linux
- Install Splunk Add-on for Sysmon for Linux
- Disable input for Add-on for Linux Sysmon:
- When both TAs use Journald for ingesting events, delete the inputs.conf file for the Add-on for Linux Sysmon folder
- When Add-on for Linux Sysmon uses File Monitoring:
- Go to Settings > Data inputs > File & Directories
- Find "/var/log/sysmon" and Disable it.
- Restart Splunk
- Update any sysmon related content as needed
The new Splunk Add-on for Sysmon For Linux will start ingesting data using Journald. The old events collected by the Add-on for Linux Sysmon will still be present in Splunk under sysmon_linux sourcetype. If switching from file to journald monitoring, some initial data duplication will occur as the Splunk Add-on for Sysmon for Linux will ingest all available events.
Configure inputs for the Splunk Add-on for Sysmon for Linux | Troubleshoot the Splunk Add-on for Sysmon For Linux |
This documentation applies to the following versions of Splunk® Supported Add-ons: released
Feedback submitted, thanks!