Thanks Diego for your response,
much appreciated.
1). On that blog, it says, we should update the
ossec.conf With this....
<localfile>
<location>Microsoft-Windows-Sysmon/Operational</location>
<log_format>eventchannel</log_format>
</localfile>
Please verify the location... As it's having forward slash, instead of backward slash.
2). About ur question of restart...I restarted the agent, i didn't restart the manager(i didn't remember this step from the blog.. let me verify and let me restart as well)
3) Do you have generated events with eventID: 17 in the Microsoft-Windows-Sysmon/Operational location from the Agent?
As suggested on the blog, i have updated the local_rules.xml file..
I am not sure how to generate eventID 17, could you please suggest me the steps.. thanks..