We want to move forward with ability to ingest and monitor sysmon events into sentinel to have forensics investigation capability enabled for windows based servers.We are looking for Microsoft-Windows-SystemSettingsV2/Operational/Performance/information events. We need this functionality ever than before in order to cater business need and would request you to have this incorporated as part of next release.

Comments

  • This is would be a vital feature of application log monitoring as the current infrastructure have a huge requirement for sysmon integration which makes the appropriate log monitoring more important.