Security Compliance
Configure the Windows Sysmon connector on a SEM appliance
This article describes how to configure the Microsoft Windows Sysmon connector on a SEM appliance.
First published date
Last published date
Overview
Product section
Resolution
To set up the connector, add a registry key, and then create a new connector on the SEM appliance.
Add a registry key
- Log in to the node or agent machine, and then open the registry editor (Regedit.exe).
- Navigate to:
Computer\HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog - Right-click EventLog, and then select New Key.
- Enter the following name for the new key:
Microsoft-Windows-Sysmon/Operational
Create a new connector on the SEM appliance
HTML5 console- In the SEM Events Console, click the Nodes tab.
- Under Refine Results, expand the Type group, and then select the Agent check box.
- Select an agent, and then click Manage node connectors.
- In the search box, enter sysmon.
- Select the connector, and then click Add Connector.
- Complete the connector configuration form. The following fields are common across most connectors:
- Name: Enter a user-friendly label for your connectors.
- Log File: Enter the location of the log file that the connector will normalize. This is a location on either the local computer (Agents), or the SEM appliance (non-Agent devices).
- Output: Normalized, Raw + Normalized, Raw. You only need to configure these values if SEM is configured to save raw (unnormalized) log messages.
- Click Add.
- Select your configured connector, and then click Start.
- On your SEM appliance, log in to the SEM web console or air console.
- On the SEM menu bar, navigate to Manage > Nodes.
- On the Nodes page, select the Windows Node that requires a connector.
- Next to the node, click
, and then select Connectors.
- In the search box, search for:
Sysmon - Select the connector.
- Click
, and then select New.
- Select the new connector.
- Next to the connector, click
, and then select Start.