# Sysmon events not getting to SOC kibana or hunt - connection issues

**URL:** <https://discuss.elastic.co/t/sysmon-events-not-getting-to-soc-kibana-or-hunt-connection-issues/327966>\
**Category:** Elastic Agent\
**Created:** [March 17, 2023, 7:26pm UTC](https://discuss.elastic.co/t/sysmon-events-not-getting-to-soc-kibana-or-hunt-connection-issues/327966 "2023-03-17T19:26:42Z")\
**Posts on this page:** 1\
**Showing post:** 24

<div class="post-metadata">

**Author:** ![iqworks](https://avatars.discourse-cdn.com/v4/letter/i/a9a28c/32.png) [@iqworks](https://discuss.elastic.co/u/iqworks)\
**Post date:** [April 17, 2023, 11:47pm UTC](https://discuss.elastic.co/t/sysmon-events-not-getting-to-soc-kibana-or-hunt-connection-issues/327966/24 "2023-04-17T23:47:57Z")

</div>

Hi, I am back from my other project. I made a new forum post ( [I am using the Sysmon-\> logstash -\> elasticsearch (ELK) architecture issues](https://discuss.elastic.co/t/i-am-using-the-sysmon-logstash-elasticsearch-elk-architecture-issues/330076) ), but realized that I already had a post about my sysmon data not getting to kibana, sorry a bout that.  
But I continue with **THIS** thread.

So, after re-reading replies to this post, I decided to  
just focus on sysmon to logstash to elasticsearch. When I lined up the IP addresses to use

This is what I have :

winlogbeat - I am using logstash output, enabled with a hosts: ["192.168.1.120:5044"].

elasticsearch.yml - network.hosts: ["192.168.1.120:9200"].  
Is there another place I need to put this IP address?  
(I changed this IP to .216 which is my SOC IP, still nothing)

logstash - creates its own pipes?

I tried to test sysmon to kibana by creating a mspaint instance process in sysmon. I looked for it in kibana, elastic sysmon logs and it says 0.

This might be a clue, but 192.168.1.120 does not ping? But data gets into kibana from my IPv4 and SOC IP?  
I saw a video that mentioned useing so-allow to enter an IP address and then going into the winlogbeat and entering that same IP address, and they called it a sensor? Where is the sensor?

Maybe I am not including the right sysmon includes or excludes, But I only changed two :  
ImageLoad onmatch="include" and  
ProcessAccess onmatch="include"  
Niether of which have any rules.

thanks again for any help or advice.

---

_[View the full topic](https://discuss.elastic.co/t/sysmon-events-not-getting-to-soc-kibana-or-hunt-connection-issues/327966)._
