We have been battling with a Sysmon Error #255 for almost a year now, across various recent versions.
Large network, 5000+ hosts, the issue seems to affect about 5% of our fleet occasionally.
We will see Error 255: Failed to allocate 40000 bytes. Exit process.
After this, logs stop flowing and the system needs to be rebooted. Restarting the process/service without a reboot is impossible. We tried everything to figure out what is causing this error but I am out of ideas. On some occasions we need to delete all the registry artifacts for Sysmon and perform a full un-install/re-install before we can get logs flowing to our SIEM again.
Can Microsoft provide some kind of documentation for the wide array of 255 errors, this '40000 bytes' is just one variant, there are many different 255 errors, some of them are sort of self explanatory but many, like this error make absolutely no sense, nor is there any way to debug what is causing it.
How can we get in contact with someone to help try and debug this issue ? Are there any debug steps we can use ourself that arent documented ?