2020-09-10 12:40 PM
Sysmon service is running and generating events that I see in Event Viewer. I've add the channel: Microsoft-Windows-Sysmon/Operational on the Log Collector. But I don't see Sysmon logs in Netwitness Investigate. I see logs from other channels. Is this a parser issue? Any help would be appreciated.
2020-09-10 01:14 PM
Jay
Do you see them at all from an unknown device type perspective? Are there any errors in the log collector winrm logs?
Dave
2020-09-13 07:46 AM
No, I don't see sysmon logs under the unknown device type or anywhere else.
No winrm logs on the collector.
2020-12-24 09:48 PM
HI Jay Alexander,
Please grant additional permissions to custom channel in windows server. This document https://community.rsa.com/docs/DOC-108785 has steps for security channel.
2023-04-12 09:58 PM
Hi @JayAlexander , Have you resolved the issue yet? and could you please let me know the reason why? Thank you very much.