File Path in configuration steps says to place .yaml file in "config" folder:
"1. Create a file in folder C:\ProgramData\Sumo Logic\OpenTelemetry Collector\config\ with name sysmon_windows.yaml."
Suggest correct path should be "C:\ProgramData\Sumo Logic\OpenTelemetry Collector\config\conf.d" as stated in the OpenTelemetry configuration yaml itself:
"## All modifications should be put as separate files in conf.d subdirectory"
In my testing, moving the sysmon_windows.yaml from "/config" and into "/config/conf.d" without any other configuration changes made, was the difference between OpenTelemetry correctly forwarding Sysmon logs, and not.
https://help.sumologic.com/docs/send-data/opentelemetry-collector/data-source-configurations/collect-logs/
File Path in configuration steps says to place .yaml file in "config" folder: "1. Create a file in folder C:\ProgramData\Sumo Logic\OpenTelemetry Collector\config\ with name sysmon_windows.yaml."
Suggest correct path should be "C:\ProgramData\Sumo Logic\OpenTelemetry Collector\config\conf.d" as stated in the OpenTelemetry configuration yaml itself: "## All modifications should be put as separate files in conf.d subdirectory"
In my testing, moving the sysmon_windows.yaml from "/config" and into "/config/conf.d" without any other configuration changes made, was the difference between OpenTelemetry correctly forwarding Sysmon logs, and not.