Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

LME 2.0 - Sysmon dashboard #521

Open
abrightman88 opened this issue Dec 2, 2024 · 1 comment
Open

LME 2.0 - Sysmon dashboard #521

abrightman88 opened this issue Dec 2, 2024 · 1 comment

Comments

@abrightman88
Copy link

Hi,

I've setup LME 2.0 and all seems good although there are no events showing under Sysmon Summary 2.0. Am I missing something? Any advise would be great

Thanks

@mreeve-snl
Copy link
Collaborator

https://github.com/cisagov/LME/blob/main/docs/markdown/reference/dashboard-descriptions.md#prerequisites
we should probably make this easier to find, hopefully the pre-reqs is helpful for everything you need to setup prior to getting the sysmon dashboards to populate.

if you've setup all the agents + sysmon service running on windows you usually need to wait for logs to start populating in elasticsearch.

If making sure all that is working... you could also try following some of the elastic agent debugging steps we've highlighted here:
https://github.com/cisagov/LME/blob/main/docs/markdown/agents/elastic-agent-mangement.md#troubleshooting-agent-setup

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
Status: 🆕 Product Backlog
Development

No branches or pull requests

2 participants