Kibana showing windows_eventlog but not sysmon

iqworks Information Quality Works 276 Reputation points
2023-05-11T14:21:51.34+00:00

Hi, I finally got windows data into security onion. But I dont see sysmon categories?

User's image

But I do show windows_events?

image

are windows_eventlogs the same as sysmon maybe? not sure.

thanks for any suggestions or advice

System Center Virtual Machine Manager
Windows 10 Security
Windows 10 Security
Windows 10: A Microsoft operating system that runs on personal computers and tablets.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
2,907 questions
Windows Server PowerShell
Windows Server PowerShell
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.PowerShell: A family of Microsoft task automation and configuration management frameworks consisting of a command-line shell and associated scripting language.
5,521 questions
Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,162 questions
0 comments No comments
{count} votes

5 answers

Sort by: Most helpful
  1. Rich Matheisen 46,711 Reputation points
    2023-05-11T14:32:04.6866667+00:00

  2. Deleted

    This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.


    Comments have been turned off. Learn more

  3. Deleted

    This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.


    Comments have been turned off. Learn more

  4. Mark Ma 0 Reputation points
    2023-05-29T07:20:41.4033333+00:00

    test again for this situation

    1.2


  5. iqworks Information Quality Works 276 Reputation points
    2023-05-29T15:23:03.7133333+00:00

    Thanks for your replies. I forgot to do this:

    setup.kibana:

    **

    
    

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.