- Download the Sysmon ZIP file and unzip it in the target system.
- Download the Sysmon configuration file to a folder and name the file sysmon_config.xml.
-
Install Sysmon in the Windows system and execute the following command:
Sysmon starts logging the information to the Windows Event Log.
- Open USM Anywhere and verify that you are receiving Sysmon events.