sysmon and bsod

claz 6 Reputation points
2022-01-25T23:34:13.843+00:00

I recently tried to install Sysmon so we can send more detailed data to our SoC. Noticed we had some servers with BSOD issues. Seems like Windows 10 has been working fine as well as Server 2012 R2. Those that have been most problematic are 2008 R2 (yes, i know its out of support and working on that) and 2012. The version of Sysmon is 13.31.

Has anyone else witnessed a BSOD just on install? Is there a version that works best? Is there a prereq that I am missing?

Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,132 questions
0 comments No comments
{count} vote

1 answer

Sort by: Most helpful
  1. Ingemar 1 Reputation point
    2022-02-17T14:35:29.883+00:00

    Just wanted to say that we experienced the same issues seeing BSOD upon Sysmon installs of version 13.31 on WS2008R2 (covered with valid ESU's). We raised a ticket and got the following recommendations from the agent:

    "At this point, it is clear that the issue is related to the sysmon which is not supported directly by us.
    Regarding your sysmon query, I think Sysinternals community will be able to answer more accurately. Although, as per my knowledge even the older versions of sysmon (version 11 and 12) had caused issues on Windows server 2008.

    We always recommend the latest version of softwares should be used on our Operating system but because you are facing issues with the latest version of sysmon, I can suggest you to try the 10.42 version on Windows server 2008. Also, please discuss this with the sysmon forum or community because they have more expertise on this."

    We may try the 10.42 on a cloned production server that we have at hand.

    BR
    Ingemar

    0 comments No comments