Closed ghost closed 4 years ago
Hi @secdev-01 , It looks like Sysmon generates events to Windows Event logs. Have you tried collecting the events from the "Applications and Services Logs/Microsoft/Windows/Sysmon/Operational" log?
I'll give that a try , thanks.
Is there currently a Windows Sysmon Source Declaration? Are there any plans to develop one?
The Sysmon collector allows for several endpoint related events to be streamed.
https://docs.microsoft.com/en-us/sysinternals/downloads/sysmon
Thank you in advance.