Winlogbeat Sysmon Registry events missing event.category


My Sysmon registry events (Registry object added or deleted (rule: RegistryEvent)) seem to be missing an event.category field. (7.8)

What event.category should be given to these Sysmon events?




Hello @willemdh ! Indeed it seems we lack a category value for registry related events. I opened an issue here to keep track of how we can improve this.

Thanks for bringing this up!

1 Like

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.