Sysmon product comparisons
The following sections describe the differences between versions 1.0.4 of the Add-on for Linux Sysmon and 1.0.0 of the Splunk Add-on for Sysmon for Linux. Note that the most significant difference is that version 1.0.0 of the Splunk Add-on has source set as journald:sysmon and sourcetype as sysmon:linux. while versions 1.0.4 of the Add-on for Linux Sysmon has source set as Syslog:Linux-Sysmon/Operational and sourcetype as sysmon_linux. See the following table for information in field changes between versions 1.0.4 of the Add-on for Linux Sysmon and 1.0.0 of the Splunk Add-on for Sysmon For Linux
Field mapping comparison for 1.0.4 of the Add-on for Linux Sysmon and 1.0.0 of the Splunk Add-on for Sysmon For Linux
Source type | EventCode | Fields added | Fields removed | Fields modified | 1.0.4 extractions | 1.0.0 extractions |
---|---|---|---|---|---|---|
sysmon:linux | 1 | dvc
user_id |
Level RecordID |
Guild Name |
"{ff032593-a8d3-4f13-b0d6-01fc615a0f97}" "Linux-Sysmon" |
{ff032593-a8d3-4f13-b0d6-01fc615a0f97} Linux-Sysmon |
sysmon:linux |
3 |
user_id |
Level src_host |
Guid Name |
"{ff032593-a8d3-4f13-b0d6-01fc615a0f97}" "Linux-Sysmon" |
{ff032593-a8d3-4f13-b0d6-01fc615a0f97} Linux-Sysmon |
sysmon:linux | 4 | dvc user |
Level RecordID |
Guid Name |
"{ff032593-a8d3-4f13-b0d6-01fc615a0f97}" "Linux-Sysmon" |
{ff032593-a8d3-4f13-b0d6-01fc615a0f97} Linux-Sysmon |
sysmon:linux | 5 | dvc user_id |
Level RecordID |
Guid Name |
"{ff032593-a8d3-4f13-b0d6-01fc615a0f97}" "Linux-Sysmon" |
{ff032593-a8d3-4f13-b0d6-01fc615a0f97} Linux-Sysmon |
sysmon:linux | 9 | dvc user_id |
Level RecordID |
Guid Name |
"{ff032593-a8d3-4f13-b0d6-01fc615a0f97}" "Linux-Sysmon" |
{ff032593-a8d3-4f13-b0d6-01fc615a0f97} Linux-Sysmon |
sysmon:linux | 11 | dvc user_id |
Level RecordID |
Guid Name |
"{ff032593-a8d3-4f13-b0d6-01fc615a0f97}" "Linux-Sysmon" |
{ff032593-a8d3-4f13-b0d6-01fc615a0f97} Linux-Sysmon |
sysmon:linux | 16 | file_path dvc |
Level RecordID |
Guid Name |
"{ff032593-a8d3-4f13-b0d6-01fc615a0f97}" "Linux-Sysmon" |
{ff032593-a8d3-4f13-b0d6-01fc615a0f97} Linux-Sysmon |
sysmon:linux | 23 | dvc user_id |
Level RecordID |
Guid Name |
"{ff032593-a8d3-4f13-b0d6-01fc615a0f97}" "Linux-Sysmon" |
{ff032593-a8d3-4f13-b0d6-01fc615a0f97} Linux-Sysmon |
Assumptions:
- Splunk Enterprise version: 9.0.1
- Sysmon For Linux version: 1.0.2
- Add-on for Linux Sysmon version: 1.0.4
- Splunk Add-on for Sysmon For Linux version: 1.0.0
- Input: Journald and File Monitoring
Initial environment configuration is a Splunk instance with the Splunk Add-on for Sysmon for Linux installed.
Troubleshoot the Splunk Add-on for Sysmon For Linux | Source types for the Splunk Add-on for Sysmon for Linux |
This documentation applies to the following versions of Splunk® Supported Add-ons: released
Feedback submitted, thanks!