Skip to content
Discussion options

You must be logged in to vote

I have added a section in our documentation about this:

https://docs.securityonion.net/en/2.3/osquery.html#shipping-windows-eventlogs

RE: anything special? No - Just install sysmon on the host with whatever config you want and configure the query as specified in the docs - keep in mind it could take up to 15min to start shipping the logs, as osquery checks in with Fleet every 10min to see if there is a config change (ie new scheduled query)

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by defensivedepth
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants