Does this help: https://medium.com/@concanno/how-to-hunt-on-sysmon-data-67f6661fd166
Kibana showing windows_eventlog but not sysmon
Hi, I finally got windows data into security onion. But I dont see sysmon categories?
But I do show windows_events?
are windows_eventlogs the same as sysmon maybe? not sure.
thanks for any suggestions or advice
5 answers
Sort by: Most helpful
-
-
Deleted
This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.
Comments have been turned off. Learn more
-
Deleted
This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.
Comments have been turned off. Learn more
-
Mark Ma 0 Reputation points
2023-05-29T07:20:41.4033333+00:00 test again for this situation
-
iqworks Information Quality Works 276 Reputation points
2023-05-29T15:23:03.7133333+00:00 Thanks for your replies. I forgot to do this:
setup.kibana:
**