Installation of Sysmon is optional, but highly recommended.
To install Sysmon
- Download the Sysmon ZIP file and unzip it in the target system.
Download the Sysmon configuration file to a folder and name the file sysmon_config.xml.
Install Sysmon in the Windows system and execute the following command:
sysmon.exe -accepteula -h md5 -n -l -i sysmon_config.xml
Sysmon starts logging the information to the Windows Event Log.
- Open USM Anywhere and verify that you are receiving Sysmon events.