Configuring Sysmon for LogMan.io¶
Microsoft Sysinternals Sysmon provides process, network, registry, and file telemetry. A large part of the Windows Sigma detections and the Sysmon window correlations in the TeskaLabs LogMan.io Common Library depend on it.
This page starts with how to deploy Sysmon and get events into LogMan.io. Technical reference (event IDs, detections) follows below.
Analyst manual
After Sysmon events arrive, validate multi-stage detections with the Advanced correlation rules guide. For writing your own window rules, see How to write a window correlation rule.
Deploy Sysmon¶
1. Install Sysmon¶
Download Sysmon and the recommended LogMan.io configuration:
Requires Sysmon 15.x or newer (schema 4.90) for full detection coverage.
On the Windows host, open an elevated command prompt and install Sysmon with that config:
sysmon64.exe -accepteula -i sysmon-config-lmio.xml
Confirm the running configuration:
sysmon64.exe -c
Update an existing install
If Sysmon is already installed, apply the LogMan.io config without reinstalling:
sysmon64.exe -c sysmon-config-lmio.xml
2. Verify the Windows Event channel¶
Sysmon writes to the Windows Event Log channel Microsoft-Windows-Sysmon/Operational.
This is a normal Windows Event channel. You can open it in Event Viewer:
- Start Event Viewer (
eventvwr.msc). - Go to Applications and Services Logs > Microsoft > Windows > Sysmon > Operational.
- Confirm that new events appear after process activity (for example Event ID 1, process creation).
If the channel is missing or empty, Sysmon is not installed correctly or is not logging.
3. Allow WEF to read the Sysmon channel¶
By default, Windows Event Forwarding cannot read the Sysmon channel. Grant Network Service (and Event Log Readers) access on each endpoint:
wevtutil.exe sl Microsoft-Windows-Sysmon/Operational /ca:O:BAG:SYD:(A;;0xf0005;;;SY)(A;;0x5;;;BA)(A;;0x1;;;S-1-5-32-573)(A;;0x1;;;NS)
This is the same pattern as for the Security log.
4. Forward events with WEC/WEF¶
Set up Windows Event Forwarding to the LogMan.io Collector as described in WEC/WEF.
The Collector already includes Microsoft-Windows-Sysmon/Operational in its default WEC queries. You do not need to add a Sysmon query manually unless you replaced the defaults with a custom queries list.
After Sysmon is installed and the channel ACL is set, events should flow with the existing WEC subscription.
5. Confirm in LogMan.io¶
In Discover, search for example:
we.channel:"Microsoft-Windows-Sysmon/Operational"event.code:1
Deploy with Active Directory¶
For domain-joined hosts, deploy Sysmon centrally instead of installing host by host.
- Place binaries on a share accessible to computers (for example
\\fileserver\lmio\sysmon\):sysmon64.exefrom Sysinternals andsysmon-config-lmio.xml. -
Install via Group Policy (computer startup script or scheduled task). Target a GPO linked to the OUs that should send Sysmon logs:
\\fileserver\lmio\sysmon\sysmon64.exe -accepteula -i \\fileserver\lmio\sysmon\sysmon-config-lmio.xmlFor updates, use
-cwith the same config path. 3. Apply the Sysmon channel ACL with the same GPO (startup script), using thewevtutilcommand from step 3 in Deploy Sysmon, so Network Service can forward the channel. 4. Reuse your WEC Group Policy from the WEC setup so computers remain subscribed to the Collector. No separate Sysmon query is required when using Collector defaults. 5. Rungpupdate /forceon a pilot host, then verify Event Viewer and Discover as above.
Deployment checklist¶
- Sysmon 15+ installed with
sysmon-config-lmio.xml - Events visible in Event Viewer under Sysmon / Operational
wevtutilACL grants Network Service read on the Sysmon channel- WEC/WEF points at the LogMan.io Collector (WEC setup)
- Events visible in Discover (
event.code:1, Sysmonwe.channel) - Optionally validate ransomware / trojan rules in the analyst guide
Reference¶
Important Windows event IDs¶
The recommended config enables the Sysmon Event IDs that TeskaLabs LogMan.io Common Library detections use. Counts change as the library evolves; treat the table as orientation.
| Event ID | Type | Notes |
|---|---|---|
| 1 | Process creation | Most Windows Sigma rules and Sysmon correlations |
| 2 | File creation time changed | |
| 3 | Network connection | Also used by Responder correlation |
| 4 | Sysmon service state | Always emitted |
| 6 | Driver loaded | |
| 7 | Image loaded | High volume; needed by some correlations |
| 8 | CreateRemoteThread | |
| 9 | RawAccessRead | |
| 10 | Process access | High volume |
| 11 | File created | Ransomware / trojan chains |
| 12-14 | Registry events | |
| 15 | FileCreateStreamHash | |
| 16 | Sysmon config change | Always emitted |
| 17-18 | Pipe created / connected | |
| 19-21 | WMI events | |
| 22 | DNS query | Also used by Responder correlation |
| 23 / 26 | File delete | |
| 25 | Process tampering | |
| 27 / 28 | File block executable / shredding | Protective; off in the shipped config |
| 29 / 30 | File executable detected | Needs Sysmon 15+ |
| 255 | Error |
Event IDs 5 (process terminated) and 24 (clipboard) are not required by the Common Library ruleset.
Related detections¶
| Library path | Role |
|---|---|
/Correlations/Microsoft/Sysmon/* |
Sysmon window correlations |
/Correlations/Advanced/* |
Multi-stage chains that also use Sysmon / Security |
/Correlations/Microsoft/Windows/Responder Machine Name Detected.yaml |
Sysmon EID 3, 22, and Security 5156 |
Lab procedures: Advanced correlation rules.
Ransomware stage 2
Some ransomware correlations also need Windows Security file-system audit events (4663 / 4656 / …), not only Sysmon Event ID 11. See Advanced correlation rules.
What Sysmon does not cover¶
Enable these separately when you need matching Sigma or correlation coverage:
- Windows Security auditing: Security log and Advanced Audit Policy
- PowerShell Script Block / Operational logging
- Vendor EDR or other ETW channels (not replaced by Sysmon)