-
Notifications
You must be signed in to change notification settings - Fork 4.9k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Update Sysmon module for v13.01 (EID 24 and 25) #24217
Comments
Pinging @elastic/security-external-integrations (Team:Security-External Integrations) |
Hi @crimsoncore - support for Sysmon v13 is being tracked in this issue, which we plan on addressing soon: #21172 Could you provide sample events (sanitised is fine) for event ID 24 and 25? Thanks! |
Log Name: Microsoft-Windows-Sysmon/Operational
|
EventID 24 Log Name: Microsoft-Windows-Sysmon/Operational
|
Thanks @crimsoncore, really helpful! Is there any chance you could export those two events to evtx from the Windows Event Viewer. We'll have all we need to update the module from there. |
Here you go |
Thanks very much @crimsoncore! FYI @andrewkroh |
Sysmon event ID 24 and 25 are missing from winlogbeat-sysmon.js
The text was updated successfully, but these errors were encountered: