Windows | Telemetry collection | Telemetry auditing
Sysmon event IDs: what to collect for threat detection
Sysmon fills the visibility gaps that default Windows auditing leaves open — but only if you collect the right event IDs. Here’s the complete event ID reference, my recommended collection tiers for threat detection, and working configurations for getting Sysmon data off the endpoint with NXLog Agent.
Sysmon (System Monitor) is a free Microsoft tool — a Windows system service and device driver — that logs detailed system activity, such as process creation, network connections, and registry changes, to the Windows Event Log.