Hey @Felix_Roessel , this is resolved now - the sysmon module does not populate event.ingested, causing the detection rule to miss, since it's specified as an override field. The solution is to remove the override.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.