Sysmon - Non-ASCII character in the ParentUser and ParentCommandLine field

Robert Morningstar 0 Reputation points
2024-07-10T15:25:31.47+00:00

Has anyone seen  this behavior with Sysmon:  getting non-ASCII characters in the ParentUser, and ParentCommandLine fields?   Sometimes it looks like another language character set, other times it is WingDings or some other non-sensical characters.     This screenshot is from Splunk and is  a screenshot of 2 devices over a 60 minute sampling window.      Only happens with Event code = 1. Cannot determine a pattern and it is a rare event. In the last 24 hour period 10 events with this issue out of 895,000,000+.

The screenshot is from a Splunk query. I have verified that the non-ASCII characters are in the native Windows event logs BEFORE they are forwarded to Splunk.

 

Bob M.

screenshot sysmon unicode characters in parentUser field

Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,152 questions
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.