Skip to content

Installation and configuration overview for the Splunk Add-on for Sysmon

Complete the following steps to install and configure this add-on:

  1. Configure your Microsoft Sysmon deployment to collect data.

    • Optionally, configure WEF/WEC support to forward and collect Sysmon events.
  2. Install your add-on: Install the Splunk Add-on for Sysmon on to your Splunk platform deployment.

  3. Configure your inputs: Configure inputs for the Splunk Add-on for Sysmon.

The Splunk Add-on for Microsoft Windows and the Splunk App for Windows Infrastructure are not required for the Splunk Add-on for Sysmon to function.