Sysmon logs are missing event.category and event.dataset #8189
-
Hello all, After installing the new sysmon modular sysmonconfig.xml, I have seen that multiple sysmon events do not have a event.category and some event.dataset. This results in a missing value in the default SOC dashboard After some research I prepose the following event.category and event.dataset values for the sysmon event.code:
Could these be added? Regards Bart |
Beta Was this translation helpful? Give feedback.
Replies: 3 comments 1 reply
-
An issue has been created to look into updating the fields with the aforementioned data. Thanks! |
Beta Was this translation helpful? Give feedback.
-
I also have this issue, thanks for raising it ! |
Beta Was this translation helpful? Give feedback.
-
This should be resolved in the upcoming Security Onion 2.3.200 release: |
Beta Was this translation helpful? Give feedback.
An issue has been created to look into updating the fields with the aforementioned data. Thanks!
#8194