name: Sysmon EventID 22 id: 911538b2-eba7-4d3e-85e8-d82d380c37bf version: 1 date: '2024-07-18' author: Patrick Bareiss, Splunk description: Data source object for Sysmon EventID 22 source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog separator: EventID configuration: https://github.com/SwiftOnSecurity/sysmon-config supported_TA: - name: Splunk Add-on for Sysmon url: https://splunkbase.splunk.com/app/5709 version: 4.0.2 fields: - _time - Channel - Computer - EventChannel - EventCode - EventData_Xml - EventDescription - EventID - EventRecordID - Guid - Image - Keywords - Level - Name - Opcode - ProcessGuid - ProcessID - ProcessId - QueryName - QueryResults - QueryStatus - RecordID - RecordNumber - RuleName - SecurityID - SystemTime - System_Props_Xml - Task - ThreadID - TimeCreated - UserID - UtcTime - Version - date_hour - date_mday - date_minute - date_month - date_second - date_wday - date_year - date_zone - dvc_nt_host - event_id - eventtype - host - id - index - linecount - process_exec - process_guid - process_name - punct - query - query_count - reply_code_id - signature - signature_id - source - sourcetype - splunk_server - src - tag - tag::eventtype - timeendpos - timestartpos - user_id - vendor_product example_log: 22542200x8000000000000000113892Microsoft-Windows-Sysmon/Operationalwin-dc-299.attackrange.local-2021-03-24 12:25:12.840{3CFDEE80-2F7D-605B-F50A-00000000AE01}717250.220.65.3.spam.dnsbl.sorbs.net9003-C:\Windows\System32\wermgr.exe