Source types for the Splunk Add-on for Sysmon for Linux
The Splunk Add-on for Sysmon for Linux supports the following sourcetypes.
Source type | Description | CIM data models |
---|---|---|
|
The Splunk Add-on for Sysmon collects data from Sysmon's dedicated Linux journald | Endpoint,
Network_Traffic |
Sysmon product comparisons | Lookups for the Splunk Add-on for Sysmon for Linux |
This documentation applies to the following versions of Splunk® Supported Add-ons: released
Feedback submitted, thanks!