Forward sysmon logs to SIEM

Jorge Tejada 1 Reputation point
2020-08-24T16:10:55.54+00:00

I am needing documentation to forward sysmon logs to a siem

Microsoft System Center
Microsoft System Center
A suite of Microsoft systems management products that offer solutions for managing datacenter resources, private clouds, and client devices.
893 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Patrick Vanreck (SWISS TXT) 15 Reputation points
    2024-06-22T14:07:10.3466667+00:00

    Hi, just use the Splunk Universalforwarder on the Clients/Servers you installed Sysmon/Sysmon64 and define in the inputs.conf of the Sysmon-TA what do you want to index. IF you do not use Splunk, then they are a lot of other similar tools doing more or less the same..

    0 comments No comments