Quantcast
Channel: Questions in topic: "universal-forwarder"
Viewing all articles
Browse latest Browse all 1551

Do I need to configure a separate receiver port for sysmon data?

$
0
0
I currently have a receiver setup and it's ingesting data from a log source. I am looking to install the Splunk Universal Forwarders on workstations to forward Sysmon. Do I need a separate receiver port for the Sysmon data, or can I also forward that to port 9997? If so, how do I set the Sysmon data to go to it's own index? Thx

Viewing all articles
Browse latest Browse all 1551

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>