I am using sysmon 3 and I believe things will need slight modifications in order to parse sysmon 3. Some of the layout such as in event ID 1 has changed.
--
You received this message because you are subscribed to a topic in the Google Groups "security-onion" group.
To unsubscribe from this topic, visit https://groups.google.com/d/topic/security-onion/BtXoridbflQ/unsubscribe.
To unsubscribe from this group and all its topics, send an email to security-onio...@googlegroups.com.
--
You received this message because you are subscribed to the Google Groups "security-onion" group.
To unsubscribe from this group and stop receiving emails from it, send an email to security-onio...@googlegroups.com.
For testing purposes, you can use the 2.9 pre-release that have it fixed.
https://groups.google.com/forum/#!topic/ossec-list/JA9x4uzDg1g
-Josh
-Josh
Yes, the pre-compiled 2.9 beta does not work for some reason - The binary that I use in dev and testing that works is from 1/15, which you are welcome to download here:
-Josh