Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

  1. Login to the Snare agent and create a new Audit Policy by going to “Audit Policy” and select “Add”.

  2. Set the “Identify the high level event” option to “Ant event(s)”.

  3. Set the “Source Search Term” to “Microsoft-Windows-Sysmon”.

  4. Check all items in “Identify the event types to be captured”.

...

  1. .

  2. Save the policy.

  3. Select the “Apply Configuration & Restart Service” option on the navigation menu.

...

Sysmon log data will now be forwarded to all configured destinations.

...