Document toolboxDocument toolbox

box.win_sysmon

Introduction

The tags beginning with box.win_sysmon identify events generated by Sysmon.

Valid tags and data tables 

The full tag must have 2 levels, fixed as box.win_sysmon. These are the valid tags and corresponding data tables that will receive the parsers' data:

Product / Service

Tags

Data tables

Product / Service

Tags

Data tables

Windows System Monitor (Sysmon)

box.win_sysmon

box.win_sysmon

For more information, read more About Devo tags.

Table structure

These are the fields displayed in this table:

box.win_sysmon

Field

Type

Source field name

Extra fields

Field

Type

Source field name

Extra fields

eventdate

timestamp

 

 

Machine

str

 

 

Datetime

str

 

 

EventID

int8

 

 

SourceName

str

 

 

Authority

str

 

 

LogLevel

str

 

 

SourceURL

str

 

 

Event

str

 

 

Rule

str

 

 

RuleName

str

 

 

UtcTime

str

 

 

ProcessGuid

str

 

 

ProcessId

str

 

 

Image

str

 

 

FileVersion

str

 

 

Description

str

 

 

Product

str

 

 

Company

str

 

 

OriginalFileName

str

 

 

CommandLine

str

 

 

CurrentDirectory

str

 

 

User

str

 

 

LogonGuid

str

 

 

LogonId

str

 

 

TerminalSessionId

str

 

 

IntegrityLevel

str

 

 

Hashes

str

 

 

ParentProcessGuid

str

 

 

ParentProcessId

str

 

 

ParentImage

str

 

 

ParentCommandLine

str

 

 

TargetFilename

str

 

 

CreationUtcTime

str

 

 

EventType

str

 

 

TargetObject

str

 

 

Details

str

 

 

Protocol

str

 

 

Initiated

str

 

 

SourceIsIpv6

str

 

 

SourceIp

str

 

 

SourceHostname

str

 

 

SourcePort

str

 

 

SourcePortName

str

 

 

DestinationIsIpv6

str

 

 

DestinationIp

str

 

 

DestinationHostname

str

 

 

DestinationPort

str

 

 

DestinationPortName

str

 

 

QueryName

str

 

 

QueryStatus

str

 

 

QueryResults

str

 

 

message

str

rawMessage

 

hostchain

str

 

✓

tag

str

 

✓

rawMessage

str

 

✓