Monitoring Splunk

What happened to sysmon.conf? [Registry Monitoring]

mleidner
New Member

I am trying to configure Windows registry monitoring via my Splunk Deployment Server but I am don't see anything in the latest Splunk documentation about sysmon.conf.

In the splunkd.log on my Windows client, I am seeing errors related to sysmon.conf such as:

INFO ExecProcessor - message from ""D:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe" --driver-path "D:\Program Files\SplunkUniversalForwarder\bin" -index regmon" splunk-regmon - SysmonMigrator::read - 'sysmon.conf' was not found, no migration is required."
INFO ExecProcessor - message from ""D:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe" --driver-path "D:\Program Files\SplunkUniversalForwarder\bin" -index regmon" splunk-regmon - No enabled entries have been found for regmon or procmon in the conf file.

However, when I go to the Splunk Documentation page, I cannot find any page for sysmon.conf to see how to properly configure it. I see sysmon.conf referenced on this page but a configuration description page does not exist. Is sysmon.conf still in use for Windows Registry Monitoring?

0 Karma

yannK
Splunk Employee
Splunk Employee

the registry monitoring are now a scripted input, part of the inputs.conf
see http://docs.splunk.com/Documentation/Splunk/5.0.5/Data/MonitorWindowsRegistrydata

0 Karma
Get Updates on the Splunk Community!

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...

Updated Team Landing Page in Splunk Observability

We’re making some changes to the team landing page in Splunk Observability, based on your feedback. The ...

New! Splunk Observability Search Enhancements for Splunk APM Services/Traces and ...

Regardless of where you are in Splunk Observability, you can search for relevant APM targets including service ...