sysmon-splunk-app
sysmon-splunk-app copied to clipboard
use Computer or ComputerName
Dashboard Splunk App Sysmon App for Splunk sysmon-splunk-app 2.0.0 App(3544) on the Status dashboard runs a query sysmon | stats count by Computer | sort - count While the TA TA-microsoft-sysmon 8.0.0 (app1914) returns the field ComputerName (So dashboard doesnot return anything in the search)
could the splunk search be changed many thanks