- Sysmon rules for the eventchannel format: https://github.com/wazuh/wazuh-ruleset/pull/285
I hope it can help, don't hesitate to reach us for further doubts.- Windows rules rework: https://github.com/wazuh/wazuh-ruleset/issues/324 and https://github.com/wazuh/wazuh-ruleset/pull/325
--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+un...@googlegroups.com.
To post to this group, send email to wa...@googlegroups.com.
Visit this group at https://groups.google.com/group/wazuh.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/6d578ec3-6280-4e80-ab8f-1659146ca478%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
You can additionally monitor specific Windows event channels. The location is the name of the event channel. This is the only way to monitor the Applications and Services logs.
That eventchannel is the only way to read events from an application log such as Sysmon.
I have verified Sysmon is installed correctly and is producing events.
I hope it helps, let us know if your issue persists or have any other doubts.<localfile><location>Microsoft-Windows-Sysmon/Operational</location><log_format>eventlog</log_format></localfile>
--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+un...@googlegroups.com.
To post to this group, send email to wa...@googlegroups.com.
Visit this group at https://groups.google.com/group/wazuh.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/829fa7d5-d3e6-4d9e-8302-59123786f941%40googlegroups.com.