Using Splunk Applications
Splunk Applications Overview
Splunk applications, or apps, are packages that extend the capabilities of Splunk Enterprise or Splunk Cloud, enabling users to manage specific types of operational data. Each app is tailored to handle data from specific technologies or use cases, acting as a pre-built knowledge package for that data. Features provided by Splunk apps include:
Custom data inputs
Custom visualizations
Dashboards, alerts, reports, and more
Installing and Using the Sysmon App for Splunk
The Sysmon App for Splunk by Mike Haag helps enhance security monitoring capabilities. Here’s how to install and configure it:
Sign Up on Splunkbase
Create a free account on Splunkbase.
Download the App
Log in to Splunkbase and locate the Sysmon App for Splunk.
Add the App to the Search Head
Navigate to the Sysmon App page, download the application, and install it on your Splunk Search Head.
Configure the Application
Adjust the app’s macros to load events accurately.
Access the Sysmon App
Go to the "Apps" menu on the Splunk home page, select the Sysmon App, and open the File Activity tab.
Set the Time Range
Set the time picker to All time and click Submit.
Troubleshooting - “Top Systems” Section Not Displaying Results
Problem: No results in the “Top Systems” section.
Solution:
Click on Edit in the upper right corner.
Modify the search to replace
ComputerwithComputerName(Sysmon Event ID 11 events useComputerNameinstead ofComputer).Click Apply to update and display results.
After these adjustments, results should populate successfully in the "Top Systems" section.
Last updated