Kibana showing windows_eventlog but not a sysmon module #10323
-
Hi, I finally got windows data into security onion. But I dont see sysmon categories? are windows_events the same as sysmon maybe? not sure. thanks for any suggestions or advice |
Beta Was this translation helpful? Give feedback.
Answered by
iqworks
May 12, 2023
Replies: 1 comment 2 replies
-
On your Windows host, did you install sysmon and configure winlogbeat to pick up the sysmon log? |
Beta Was this translation helpful? Give feedback.
2 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
HI Doug thanks for the links! I will review them. I am back on my other project right now, but will be back in a couple weeks.