Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

 
 

Add Sysmon to your existing Windows event sources

You can use an update script to configure agents to collect Sysmon events.

To collect Sysmon events along with your System, Application, and Security events, add the following update script to your patches directory:

This script adds Sysmon to your Local sources.