Replies: 2 comments 4 replies
-
Are you seeing the other Windows Event logs in Security Onion, just not Sysmon? Or is everything missing? |
Beta Was this translation helpful? Give feedback.
4 replies
-
Yes, I downloaded it from SOC. I do not have any logs. |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
-
I have a home lab with Security Onion and a couple Windows machines. I have installed sysmon and winlogbeat on the windows machines following the Security Onion video on the subject (https://www.youtube.com/watch?v=Xz-7oDrZdQY). However, I am not seeing any sysmon events show up in Security Onion. All the services are up and running on Security Onion. I've configured Logstash Beat to accept all machines in the network in so-allow. Winlogbeat service has been enabled.
Beta Was this translation helpful? Give feedback.
All reactions