Skip to content

Configuring Sysmon for LogMan.io

Microsoft Sysinternals Sysmon provides process, network, registry, and file telemetry. A large part of the Windows Sigma detections and the Sysmon window correlations in the TeskaLabs LogMan.io Common Library depend on it.

This page starts with how to deploy Sysmon and get events into LogMan.io. Technical reference (event IDs, detections) follows below.

Analyst manual

After Sysmon events arrive, validate multi-stage detections with the Advanced correlation rules guide. For writing your own window rules, see How to write a window correlation rule.

Deploy Sysmon

1. Install Sysmon

Download Sysmon and the recommended LogMan.io configuration:

sysmon-config-lmio.xml

Requires Sysmon 15.x or newer (schema 4.90) for full detection coverage.

On the Windows host, open an elevated command prompt and install Sysmon with that config:

sysmon64.exe -accepteula -i sysmon-config-lmio.xml

Confirm the running configuration:

sysmon64.exe -c

Update an existing install

If Sysmon is already installed, apply the LogMan.io config without reinstalling:

sysmon64.exe -c sysmon-config-lmio.xml

2. Verify the Windows Event channel

Sysmon writes to the Windows Event Log channel Microsoft-Windows-Sysmon/Operational.

This is a normal Windows Event channel. You can open it in Event Viewer:

  1. Start Event Viewer (eventvwr.msc).
  2. Go to Applications and Services Logs > Microsoft > Windows > Sysmon > Operational.
  3. Confirm that new events appear after process activity (for example Event ID 1, process creation).

If the channel is missing or empty, Sysmon is not installed correctly or is not logging.

3. Allow WEF to read the Sysmon channel

By default, Windows Event Forwarding cannot read the Sysmon channel. Grant Network Service (and Event Log Readers) access on each endpoint:

wevtutil.exe sl Microsoft-Windows-Sysmon/Operational /ca:O:BAG:SYD:(A;;0xf0005;;;SY)(A;;0x5;;;BA)(A;;0x1;;;S-1-5-32-573)(A;;0x1;;;NS)

This is the same pattern as for the Security log.

4. Forward events with WEC/WEF

Set up Windows Event Forwarding to the LogMan.io Collector as described in WEC/WEF.

The Collector already includes Microsoft-Windows-Sysmon/Operational in its default WEC queries. You do not need to add a Sysmon query manually unless you replaced the defaults with a custom queries list.

After Sysmon is installed and the channel ACL is set, events should flow with the existing WEC subscription.

5. Confirm in LogMan.io

In Discover, search for example:

  • we.channel:"Microsoft-Windows-Sysmon/Operational"
  • event.code:1

Deploy with Active Directory

For domain-joined hosts, deploy Sysmon centrally instead of installing host by host.

  1. Place binaries on a share accessible to computers (for example \\fileserver\lmio\sysmon\): sysmon64.exe from Sysinternals and sysmon-config-lmio.xml.
  2. Install via Group Policy (computer startup script or scheduled task). Target a GPO linked to the OUs that should send Sysmon logs:

    \\fileserver\lmio\sysmon\sysmon64.exe -accepteula -i \\fileserver\lmio\sysmon\sysmon-config-lmio.xml
    

    For updates, use -c with the same config path. 3. Apply the Sysmon channel ACL with the same GPO (startup script), using the wevtutil command from step 3 in Deploy Sysmon, so Network Service can forward the channel. 4. Reuse your WEC Group Policy from the WEC setup so computers remain subscribed to the Collector. No separate Sysmon query is required when using Collector defaults. 5. Run gpupdate /force on a pilot host, then verify Event Viewer and Discover as above.

Deployment checklist

  1. Sysmon 15+ installed with sysmon-config-lmio.xml
  2. Events visible in Event Viewer under Sysmon / Operational
  3. wevtutil ACL grants Network Service read on the Sysmon channel
  4. WEC/WEF points at the LogMan.io Collector (WEC setup)
  5. Events visible in Discover (event.code:1, Sysmon we.channel)
  6. Optionally validate ransomware / trojan rules in the analyst guide

Reference

Important Windows event IDs

The recommended config enables the Sysmon Event IDs that TeskaLabs LogMan.io Common Library detections use. Counts change as the library evolves; treat the table as orientation.

Event ID Type Notes
1 Process creation Most Windows Sigma rules and Sysmon correlations
2 File creation time changed
3 Network connection Also used by Responder correlation
4 Sysmon service state Always emitted
6 Driver loaded
7 Image loaded High volume; needed by some correlations
8 CreateRemoteThread
9 RawAccessRead
10 Process access High volume
11 File created Ransomware / trojan chains
12-14 Registry events
15 FileCreateStreamHash
16 Sysmon config change Always emitted
17-18 Pipe created / connected
19-21 WMI events
22 DNS query Also used by Responder correlation
23 / 26 File delete
25 Process tampering
27 / 28 File block executable / shredding Protective; off in the shipped config
29 / 30 File executable detected Needs Sysmon 15+
255 Error

Event IDs 5 (process terminated) and 24 (clipboard) are not required by the Common Library ruleset.

Library path Role
/Correlations/Microsoft/Sysmon/* Sysmon window correlations
/Correlations/Advanced/* Multi-stage chains that also use Sysmon / Security
/Correlations/Microsoft/Windows/Responder Machine Name Detected.yaml Sysmon EID 3, 22, and Security 5156

Lab procedures: Advanced correlation rules.

Ransomware stage 2

Some ransomware correlations also need Windows Security file-system audit events (4663 / 4656 / …), not only Sysmon Event ID 11. See Advanced correlation rules.

What Sysmon does not cover

Enable these separately when you need matching Sigma or correlation coverage:

  • Windows Security auditing: Security log and Advanced Audit Policy
  • PowerShell Script Block / Operational logging
  • Vendor EDR or other ETW channels (not replaced by Sysmon)

See also