SwiftOnSecurity / sysmon-config

Sysmon configuration file template with default high-quality event tracing
4.82k stars 1.71k forks source link

Sysmon installation issue #129

Open MarkAndreson opened 4 years ago

MarkAndreson commented 4 years ago

Hi,

Need help with installing Sysmon on Windows 10 and Windows Server 2012 R2. I am getting the following error after running the command: sysmon64.exe -i

ERROR wevtutil.exe returned failure Event manifest installation failed with last error Access denied

Kindly help

pr3l14t0r commented 4 years ago

Heyho! :) "Access denied" --> Did you run it as administrator? You'll need to install it as administrator both on DC and Workstation. For workstation i'd suggest to implement a GPO that installs it for you :)