Security Compliance

Configure the Windows Sysmon connector on a SEM appliance

This article describes how to configure the Microsoft Windows Sysmon connector on a SEM appliance.

First published date

10/30/2018 8:23 PM

Last published date

10/28/2019 3:34 PM

Overview

This article describes how to configure the Windows Sysmon connector and set up your Security Event Manager (formerly Log & Event Manager) web console to communicate with the connector. 

Product section

Security Event Manager

Resolution

To set up the connector, add a registry key, and then create a new connector on the SEM appliance.

Add a registry key 

  1. Log in to the node or agent machine, and then open the registry editor (Regedit.exe).
  2. Navigate to:
    Computer\HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog
  3. Right-click EventLog, and then select New Key.
  4. Enter the following name for the new key:
    Microsoft-Windows-Sysmon/Operational

Create a new connector on the SEM appliance 

HTML5 console
  1. In the SEM Events Console, click the Nodes tab.
  2. Under Refine Results, expand the Type group, and then select the Agent check box.
  3. Select an agent, and then click Manage node connectors. 
  4. In the search box, enter sysmon.
  5. Select the connector, and then click Add Connector.
  6. Complete the connector configuration form. The following fields are common across most connectors:
    • Name: Enter a user-friendly label for your connectors.
    • Log File: Enter the location of the log file that the connector will normalize. This is a location on either the local computer (Agents), or the SEM appliance (non-Agent devices).
    • Output: Normalized, Raw + Normalized, Raw. You only need to configure these values if SEM is configured to save raw (unnormalized) log messages.
  7. Click Add.
  8. Select your configured connector, and then click Start.
Flash console
  1. On your SEM appliance, log in to the SEM web console or air console.
  2. On the SEM menu bar, navigate to Manage > Nodes.

  3. On the Nodes page, select the Windows Node that requires a connector.
  4. Next to the node, click , and then select Connectors. 
  5. In the search box, search for:
    Sysmon
  6. Select the connector.
  7. Click , and then select New.
  8. Select the new connector.
  9. Next to the connector, click ,  and then select Start.