Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

Sysmon Event 11 (File Create) Not Logging for Files Created in User Profile #867

Open
mbabinski opened this issue Nov 9, 2022 · 0 comments

Comments

@mbabinski
Copy link

  • Operating System Version: Windows 10
  • Deploying via (VirtualBox/VMWare/AWS/Azure/ESXi): VirtualBox
  • Vagrant Version (if applicable): 2.3.2

Hello! I noticed that sysmon event 11, file creation, is not logging for files created under certain directories, such as the user profile on win10.windomain.local or wef.windomain.local. I looked through the sysmon config file located at C:\ProgramData\Sysmon on wef.windomain.local and didn't see any rules that would exclude this.

On Win10, running this command:
image
...I see the following sysmon log:

image

However, running the following:
image

I don't see the log in Splunk or the Event Viewer on Win10.

Any suggestions on what may be causing this?

Thanks, and love the project btw!

# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant