It's important to mention that Sysmon isn’t required in many cases as we already have you covered with our native events. Check this article to see how LimaCharlie events map with Sysmon events on Windows.
If, however, you decide that you still need Sysmon, below are the details of how to deploy and get Sysmon data from your Windows endpoints into LimaCharlie.
Get Sysmon Data Flowing into LimaCharlie
2. Go to the Exfil Control section add a rule to bring in Windows Event Log (WEL) events.
3. Go to the Artifact Collection section and add a new collection rule with the following path to bring in all Sysmon events:
Note: You can filter the events by ID to only import select events by using the following Patterns:
Verifying Successful Setup
4. Allow up to 10 minutes for data to come into LimaCharlie after setting up a new Artifact Collection rule. Data will flow in real-time after that point.
5. Go to the Timeline view of an endpoint that has Sysmon and the LimaCharlie agent installed.
Set the *Event Type* to WEL and use the *Search* criteria: `Microsoft-Windows-Sysmon`