Monitoring Splunk

What happened to sysmon.conf? [Registry Monitoring]

mleidner
New Member

I am trying to configure Windows registry monitoring via my Splunk Deployment Server but I am don't see anything in the latest Splunk documentation about sysmon.conf.

In the splunkd.log on my Windows client, I am seeing errors related to sysmon.conf such as:

INFO ExecProcessor - message from ""D:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe" --driver-path "D:\Program Files\SplunkUniversalForwarder\bin" -index regmon" splunk-regmon - SysmonMigrator::read - 'sysmon.conf' was not found, no migration is required."
INFO ExecProcessor - message from ""D:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe" --driver-path "D:\Program Files\SplunkUniversalForwarder\bin" -index regmon" splunk-regmon - No enabled entries have been found for regmon or procmon in the conf file.

However, when I go to the Splunk Documentation page, I cannot find any page for sysmon.conf to see how to properly configure it. I see sysmon.conf referenced on this page but a configuration description page does not exist. Is sysmon.conf still in use for Windows Registry Monitoring?

0 Karma

yannK
Splunk Employee
Splunk Employee

the registry monitoring are now a scripted input, part of the inputs.conf
see http://docs.splunk.com/Documentation/Splunk/5.0.5/Data/MonitorWindowsRegistrydata

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...