Internal : Hi Metrics / Windows peeps what am I missing can metricbeat -> system > processes not detect sysmon process. I have metricbeat set to collect all processess ... I see them Alll ... but I don't see Sysmon ... it is running... It is a special processs of something that can not be detected?
Answer
yes, it's (sysmon) is a protected process now (as of version 15) so it can not be monitored with normal methods. Perhaps osquery might be able to help, using the services table
Seems like very basic monitoring feature to be able to get CPU from important processes such as lsass, but also Sysmon, Defender, Elastic Agent etc.....
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.