Skip to main content

Sysmon Solution

Purpose

This solution provides full lifecycle management for Sysmon, including installation, uninstallation, and control of all related Sysmon services.

Associated Content

ContentTypeFunction
Enable Sysmon Installation Custom FieldCustom field to handle installation Sysmon on windows machines.
Sysmon ConfigFile DownloadURLCustom FieldSpecify the file path of the Sysmon configuration file that will be used for applying the Sysmon settings
Exclude Sysmon InstallationCustom FieldCustom field to exclude site/endpoint from deploying the Sysmon installation.
Sysmon DeploymentGroupContains the machines which are opted for sysmon deployment.
Machines with SysmonGroupIncludes machines with Sysmon installed on them.
Sysmon - InstallTaskInstalls Sysmon application on windows machines.
Sysmon - UninstallTaskUninstalls Sysmon application on windows machines.
Sysmon64 ServiceMonitorsMonitors Sysmon64 Service on 64-bit Windows machines.
Sysmon ServiceMonitorsMonitors Sysmon Service on 32-bit Windows machines.

Implementation

Changelog

2026-03-26

  • Initial version of the document