Sysmon Events shifted fields

Stefan Drees 0 Reputation points
2023-02-21T12:20:23.9666667+00:00

Hi,

i have strange issues with sysmon and don't know how to fix it.

Events where forwarded by WEF to a collector. Some ProcessCreate events have shifted fields, e.g. "Rulename" has date/time value, "UTCTime" has ProcessGUID value, "Image" has FileVersion value and so on but some later fields like "ParentImage" have the correct value.

I checked the events on some systems with shifted events and not all ProcessCreate events are shifted, so it seems not a generally issue.

I'm using sysmon 14.13 but also had the same problem with sysmon 13.20.

With sysmon 13.20 i could fix this by changing the ContentFormat to RenderedText.

Because of Windows 11, i had to change it back to Events, otherwise the events would be cut off. "Message=" ist empty.

I hope, someone can help me.

Thanks

Regards

Stefan

Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,213 questions
0 comments No comments
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.