# No event collected from Sysmon

**URL:** <https://discuss.elastic.co/t/no-event-collected-from-sysmon/278147>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [July 8, 2021, 7:47am UTC](https://discuss.elastic.co/t/no-event-collected-from-sysmon/278147 "2021-07-08T07:47:50Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![bilel\_meddeb](https://avatars.discourse-cdn.com/v4/letter/b/47e85d/32.png) [@bilel\_meddeb](https://discuss.elastic.co/u/bilel_meddeb)\
**Post date:** [July 8, 2021, 7:47am UTC](https://discuss.elastic.co/t/no-event-collected-from-sysmon/278147/1 "2021-07-08T07:47:50Z")

</div>

HELLO,  
I have installed sysmon in a Windows machine using the command:

==\> sysmon.exe -i -accepteula -h md5,sha256,imphash -l -n

And then restart winlogbeat. In winlogbeat log everything is working well, and i have logs like that:

```auto
020-11-26T14:45:30.485+0100	INFO	beater/eventlogger.go:88	EventLog[Microsoft-Windows-Sysmon/Operational] successfully published 1 events

```

but when I go to kibana I am not seeing any sysmon logs

Can you tell me what's the problem please ?

Thanks for your help

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 5, 2021, 7:47am UTC](https://discuss.elastic.co/t/no-event-collected-from-sysmon/278147/2 "2021-08-05T07:47:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
