Sysmon 13.0 Config (System Error 1067)

Zane Gittins 21 Reputation points
2021-01-13T00:35:42.853+00:00

Is Sysmon 13.0 backwards compatible with older configs ? Using SwiftOnSecurity's config with Sysmon 13.0 yields an error when trying to start the Sysmon64 service. No errors about the config are thrown when installing Sysmon 13.0, however upon trying to start the service an error occurs.

During the install Sysmon says the configuration file has been validated, but seems to cause issues when starting the service.

Steps to reproduce:

  1. Download Sysmon 13.0
  2. Download SwiftOnSecurity config, save as config.xml
  3. Sysmon64.exe -i config.xml
  4. net start Sysmon64

"The Sysmon64 service is starting.
The Sysmon64 service could not be started.

A system error has occurred.

System error 1067 has occurred.

The process terminated unexpectedly."

Tested on a fresh Windows 10 install.

Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,132 questions
0 comments No comments
{count} votes

0 additional answers

Sort by: Most helpful