Hi Facundo,
I was able to see the following in the archives.log file
2022 Sep 06 13:27:00 (CitrixBackup) 192.168.2.246->EventChannel {"win":{"system":{"providerName":"Microsoft-Windows-Sysmon","providerGuid":"{5770385f-c22a-43e0-bf4c-06f5698ffbd9}","eventID":"10","version":"3","level":"4","task":"10","opcode":"0","keywords":"0x8000000000000000","systemTime":"2022-09-06T17:26:57.866592300Z","eventRecordID":"128628","processID":"5644","threadID":"2864","channel":"Microsoft-Windows-Sysmon/Operational","computer":"WSUS-Server","severityValue":"INFORMATION","message":"\"Process accessed:\r\nRuleName: technique_id=T1055.001,technique_name=Dynamic-link Library Injection\r\nUtcTime: 2022-09-06 17:26:57.866\r\nSourceProcessGUID: {c28c12a9-226e-62f4-a900-000000004c00}\r\nSourceProcessId: 5672\r\nSourceThreadId: 4212\r\nSourceImage: C:\\Program Files\\Metricbeat\\metricbeat.exe\r\nTargetProcessGUID: {c28c12a9-82c7-6317-e442-000000004c00}\r\nTargetProcessId: 6896\r\nTargetImage: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\r\nGrantedAccess: 0x1010\r\nCallTrace: C:\\Windows\\SYSTEM32\\ntdll.dll+a0be4|C:\\Windows\\System32\\KERNELBASE.dll+2126e|C:\\Program Files\\Metricbeat\\metricbeat.exe+6dbbe|UNKNOWN(000000000000040C)\r\nSourceUser: NT AUTHORITY\\SYSTEM\r\nTargetUser: I""},"eventdata":{"ruleName":"technique_id=T1055.001,technique_name=Dynamic-link Library Injection","utcTime":"2022-09-06 17:26:57.866","sourceProcessGUID":"{c28c12a9-226e-62f4-a900-000000004c00}","sourceProcessId":"5672","sourceThreadId":"4212","sourceImage":"C:\\\\Program Files\\\\Metricbeat\\\\metricbeat.exe","targetProcessGUID":"{c28c12a9-82c7-6317-e442-000000004c00}","targetProcessId":"6896","targetImage":"C:\\\\Windows\\\\System32\\\\WindowsPowerShell\\\\v1.0\\\\powershell.exe","grantedAccess":"0x1010","callTrace":"C:\\\\Windows\\\\SYSTEM32\\\\ntdll.dll+a0be4|C:\\\\Windows\\\\System32\\\\KERNELBASE.dll+2126e|C:\\\\Program Files\\\\Metricbeat\\\\metricbeat.exe+6dbbe|UNKNOWN(000000000000040C)","sourceUser":"NT AUTHORITY\\\\SYSTEM"
Does this mean it's working? If yes, where in the manager GUI do I go to look at
Thanks
Monah