Sysmon Events shifted fields
Hi,
i have strange issues with sysmon and don't know how to fix it.
Events where forwarded by WEF to a collector. Some ProcessCreate events have shifted fields, e.g. "Rulename" has date/time value, "UTCTime" has ProcessGUID value, "Image" has FileVersion value and so on but some later fields like "ParentImage" have the correct value.
I checked the events on some systems with shifted events and not all ProcessCreate events are shifted, so it seems not a generally issue.
I'm using sysmon 14.13 but also had the same problem with sysmon 13.20.
With sysmon 13.20 i could fix this by changing the ContentFormat to RenderedText.
Because of Windows 11, i had to change it back to Events, otherwise the events would be cut off. "Message=" ist empty.
I hope, someone can help me.
Thanks
Regards
Stefan