This App wasn't working in my Splunk ... noticed my Sysmon was [WinEventLog:Microsoft-Windows-Sysmon/Operational]
vs original [XmlWinEventLog:Microsoft-Windows-Sysmon/Operational] ... Maybe due to Sysmon Splunk TA installed? Added above to cover both cases
This App wasn't working in my Splunk ... noticed my Sysmon was [WinEventLog:Microsoft-Windows-Sysmon/Operational] vs original [XmlWinEventLog:Microsoft-Windows-Sysmon/Operational] ... Maybe due to Sysmon Splunk TA installed? Added above to cover both cases