Sysmon and Windows Defender

So currently I’m replacing our old graylog server, we implemented windows defender and now we’re not getting data. So we are rebuilding from scratch as I got Ubuntu 24.04 LTS installed I’m wondering is it possible to run sysmon and windows defender together with Graylog certainly there would be some overlap but can this be done in graylog 6.1a?

What do you mean “together” you want to get logs from both sysmon and defender?

yes, I see there is a sysmon/defender config from oalaf on git just wondering if it can work in graylog or anyone has done it

Yeah, it should work. Symon and Defender normally log everything to Windows events, so you are just ingesting the Windows events into Graylog.

1 Like