Sysmon Failing to write To Op log

Brian Keller 0 Reputation points
2023-04-27T13:22:17.33+00:00

I have one server of a couple thousand that won't run Sysmon. It is a 2012R2 box. The Event Viewer container is present with one entry in the op log that the config has changed. There is no service running and an system event message: The event logging service encountered an error (5) while enabling publisher {5770385f-c22a-43e0-bf4c-06f5698ffbd9} to channel Microsoft-Windows-Sysmon/Operational

I cannot uninstall as Sysmon is not seen as installed. I cannot install with the error: Configuration file validated.

wevtutil.exe returned failure

Event manifest installation failed with last error:

Cannot create a file when that file already exists.

Any help appreciated

Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,132 questions
{count} votes