Hello Joshua,
So you could add the corresponding group to the 6 last rules, here is how it would look like:
```
<rule id="255084" level="3">
<if_group>sysmon</if_group>
<field name="win.system.eventID">1</field>
<description>Windows Sysmon Event 1: Process creation</description>
<options>no_full_log</options>
<group>sysmon_event_1</group>
</rule>
<rule id="255082" level="3">
<if_group>sysmon</if_group>
<field name="win.system.eventID">3</field>
<description>Windows Sysmon Event 3: Network connection detected</description>
<options>no_full_log</options>
<group>sysmon_event_3</group>
</rule>
<rule id="255085" level="3">
<if_group>sysmon</if_group>
<field name="win.system.eventID">6</field>
<description>Windows Sysmon Event 6: Driver loaded</description>
<options>no_full_log</options>
<group>sysmon_event_6</group>
</rule>
<rule id="255083" level="3">
<if_group>sysmon</if_group>
<field name="win.system.eventID">7</field>
<description>Windows Sysmon Event 7: Image loaded</description>
<options>no_full_log</options>
<group>sysmon_event_7</group>
</rule>
<rule id="255086" level="3">
<if_group>sysmon</if_group>
<field name="win.system.eventID">15</field>
<description>Windows Sysmon Event 15: File CreateStreamHash</description>
<options>no_full_log</options>
<group>sysmon_event_15</group>
</rule>
<rule id="255081" level="3">
<if_group>sysmon</if_group>
<field name="win.system.eventID">22</field>
<description>Windows Sysmon Event 22: DNSServerInfo</description>
<options>no_full_log</options>
<group>sysmon_event_22</group>
</rule>
```
If you also want to remove the `sysmon_process-anomalies` group you can add them to a new group like this:
```
<!--
Rules from https://github.com/Neo23x0/sigma/tree/master/rules/windows/sysmon
@smtszk
updated by @nissy34
-->
<!-- Sysmon Wazuh Rules version 1.0-->
<group name="sysmon,sysmon_process-anomalies,">
<rule id="255000" level="12">
<if_group>sysmon_event1</if_group>
<field name="win.eventdata.image">\\powershell.exe||\\.ps1||\\.ps2</field>
<description>Sysmon - Event 1: Powershell or Script Execution: $(win.eventdata.image)</description>
</rule>
</group>
<!-- 6 last rules only have the group sysmon and their own group (sysmon_event_ID) -->
<group name="sysmon,">
<rule id="255084" level="3">
<if_group>sysmon</if_group>
<field name="win.system.eventID">1</field>
<description>Windows Sysmon Event 1: Process creation</description>
<options>no_full_log</options>
<group>sysmon_event_1</group>
</rule>
<rule id="255082" level="3">
<if_group>sysmon</if_group>
<field name="win.system.eventID">3</field>
<description>Windows Sysmon Event 3: Network connection detected</description>
<options>no_full_log</options>
<group>sysmon_event_3</group>
</rule>
<rule id="255085" level="3">
<if_group>sysmon</if_group>
<field name="win.system.eventID">6</field>
<description>Windows Sysmon Event 6: Driver loaded</description>
<options>no_full_log</options>
<group>sysmon_event_6</group>
</rule>
<rule id="255083" level="3">
<if_group>sysmon</if_group>
<field name="win.system.eventID">7</field>
<description>Windows Sysmon Event 7: Image loaded</description>
<options>no_full_log</options>
<group>sysmon_event_7</group>
</rule>
<rule id="255086" level="3">
<if_group>sysmon</if_group>
<field name="win.system.eventID">15</field>
<description>Windows Sysmon Event 15: File CreateStreamHash</description>
<options>no_full_log</options>
<group>sysmon_event_15</group>
</rule>
<rule id="255081" level="3">
<if_group>sysmon</if_group>
<field name="win.system.eventID">22</field>
<description>Windows Sysmon Event 22: DNSServerInfo</description>
<options>no_full_log</options>
<group>sysmon_event_22</group>
</rule>
</group>
```
We hope you find this information useful.
Regards,
Juan Manuel