Closed bmk666 closed 5 years ago
First, nice app!
Im using sysmon v8.0 and i have figured out that i needed some field aliases to get your app running in splunk.
CommandLine = process_command_line EventID = event_id process = process_name
can be that there are some more!
BR, BMK
sry, found the field transforms in the props.conf!
First, nice app!
Im using sysmon v8.0 and i have figured out that i needed some field aliases to get your app running in splunk.
CommandLine = process_command_line EventID = event_id process = process_name
can be that there are some more!
BR, BMK