4.2 ‐ Customize to Your Environment
Nasreddine Bencherchali edited this page 2026-08-14 17:39:22 +02:00

Customizing Source Types with Macros

When customizing security-content to fit your organization and Splunk deployment, one of the key things to change is what names your different source types have. A great example of this is sysmon data. If collected using the latest Splunk Add-On for Sysmon, it will automatically be source typed with sourcetype=XmlWinEventLog:Microsoft-Windows-Sysmon/Operational

This might not be the exact source type used in your organization and Splunk deployment. However, to set your own, simply modify the file: security-content/macros/sysmon.yml and change the value of definition. Other, great examples are okta, wmi, and streams http.