Sysmon log

Prev Next

Sysmon installs a service and a driver that allows for logging system activity to the Windows event log. It monitors process creation, network connections, and changes to the file creation time of a file, among other things. From a Windows logging perspective, this may be one of the most useful logs to generate that is not on by default. The following table lists events in the Microsoft-Windows-Sysmon/Operational log.

Number of occurrences in rules

Eventid

Event source or category

11

1

Microsoft-Windows-Sysmon/Operational

1

2

Microsoft-Windows-Sysmon/Operational