cisagov / LME

Logging Made Easy (LME) is a no-cost and open logging and protective monitoring solution serving all organizations.
https://www.cisa.gov/resources-tools/services/logging-made-easy
Other
765 stars 60 forks source link

Look at latest Sysmon release #56

Open llwaterhouse opened 7 months ago

llwaterhouse commented 7 months ago

What side effects will there be? Will the uninstall Sysmon script be useful when updating Sysmon?

dkorzhevin commented 7 months ago

Uninstall script will work with latest sysmon version

llwaterhouse commented 5 months ago

Should we choose a version of Sysmon for our users? What problems could occur if we don't know which version of Sysmon they're using?

cbaxley commented 5 months ago

We also need to add in a todo to update the installers to allow for a sysmon version. I am just grabbing the one from the readme.

llwaterhouse commented 5 months ago

I believe the link in the Readme always points to the latest version of Sysmon. So we don't know what version of Sysmon they are using. Do we tell them how to update their version of Sysmon? I only see instructions when they're going from 0.5 to 1.0, not later on.

Does it matter if different clients are using different versions of Sysmon? or sysmon.xml?

What are the implications of using a different sysmon.xml file? Could the user change the sysmon.xml file down the road if they want to use the more robust version?