How to add 'Microsoft-Windows-Sysmon' events to table 'SysmonEvent'?

Copper Contributor

Hi everyone.

How to add 'Microsoft-Windows-Sysmon' events to table 'SysmonEvent'?

I've try to setup it in my env w/ Win10, but Sysmon logs collected to 'Events' table only.

What I did wrong?

 

Environment:
- Azure Sentinel instance
- Data collector Security Events - Minimal.
Advanced settings: 
    * Connected Sources Windows Agent (64 bit) installed on Win10
    * Data Windows events 'Microsoft-Windows-Sysmon/Operational'

 

4 Replies

@Eliav Levi: Is this something you can speak to? 

@m0l0chI'm having a similar problem. I think I got a little farther than you might have, but now I'm seeing Sysmon events in the wrong table, or at least I think it's the wrong table. 

 

Instead of appearing in the Security/Sysmon table, I get them in the Log Management/Event table. Maybe I configured the Data settings incorrectly (see below), but...  

sysmon_in_event_table.png

Where I expected to see Sysmon events, but don't...

NotInSysmonEventTable.png

 

My Windows Event Logs Data settings...

dataconfig.png 

 

I would like to get them here in SysmonEvents

 

SysmonEvents.PNG

 

@PeterSchawacker 

 

@Ofer_Shezaf: Is this something you can speak to?