1,092 questions
Hi, just use the Splunk Universalforwarder on the Clients/Servers you installed Sysmon/Sysmon64 and define in the inputs.conf of the Sysmon-TA what do you want to index. IF you do not use Splunk, then they are a lot of other similar tools doing more or less the same..