As the topic says, we upgraded both our DEV and PROD clusters to ElasticStack 8.19.2 (DEV) or 8.19.0 (PROD) we notice that on all our Windows hosts that run agent version 8.19.x, the logging of SYSMON is no longer forwarded to the ElasticStack. Completely stopped. Previously we ran 8.18.2 when it still worked fine.
The agents that still run 8.18.2 do still log sysmon events.
We tried to downgrade the agent version to 8.18.2 but that is not supported, it’s fleet-managed.
Now what to do?