What's Up With Sysmon and the Windows Event Viewer?

  Рет қаралды 35,242

Level1Techs

Level1Techs

2 жыл бұрын

SwiftOnSecurity's Sysmon XML Config file: github.com/SwiftOnSecurity/sy...
Remote desktop tracking article: woshub.com/rdp-connection-logs...
Forum thread coming soon!
**********************************
Check us out online at the following places:
+ Website: level1techs.com/
+ Forums: forum.level1techs.com/
+ Store: store.level1techs.com/
+ Patreon: / level1
+ L1 Twitter: / level1techs
+ L1/PGP Streaming: / teampgp
+ Business Inquiries/Brand Integrations: Queries@level1techs.com
IMPORTANT Any email lacking “level1techs.com” should be ignored and immediately reported to Queries@level1techs.com.
-------------------------------------------------------------------------------------------------------------
Intro and Outro Music By: Kevin MacLeod (incompetech.com)
Licensed under Creative Commons: By Attribution 3.0 License
creativecommons.org/licenses/b...

Пікірлер: 97
@50PullUps
@50PullUps 2 жыл бұрын
As I was learning the basics of IT, discovering tools like Sysmon & PsExec was a "red pill" experience. The Sysinternals book by Russinovich and Margosis has a chapter dedicated to Sysmon that's essential reading for any Windows sysadmin.
@TheStevenWhiting
@TheStevenWhiting 2 жыл бұрын
Look back at all Mark's Case of the Unexplained and Aaron's talks. You'll learn a lot from them. I have most of them on my channel as Microsoft lost a lot of them, Mark has some on his. I watch them while working, have them running in background to listen to. Quite a few times I'll hear them talk about something I've not noticed before and will watch the video again. Learn something new every time.
@50PullUps
@50PullUps 2 жыл бұрын
@@TheStevenWhiting I'm already a subscriber of your channel :)
@TheStevenWhiting
@TheStevenWhiting 2 жыл бұрын
@@50PullUps Nice :)
@pcsecuritychannel
@pcsecuritychannel 2 жыл бұрын
Great video! I might also make a video on this showcasing how you can detect Malware on Event Viewer.
@MrLunithy
@MrLunithy 2 жыл бұрын
Also good for working out why something does not work.
@TheKazragore
@TheKazragore 2 жыл бұрын
The Event Viewer is also maliciously used by scammers to make people think there are things wrong with their computer to try and get them to pay for a solution. More explanations about how it works being out in the wild, such as this, is a great thing to help educate people!
@MrMcPeon
@MrMcPeon 2 жыл бұрын
Ingest that data into a big data system like splunk, and you basically have a Security Information & Event Managent (SIEM) system. With these tools you can run automated searches on scale over your whole infrastructure, which then again notifies you if anything malicious is found. In a nutshell a security analysts job in a security operations center.
@GeoffSeeley
@GeoffSeeley 2 жыл бұрын
As someone who has trolled through the Windows Event log for decades looking for cryptic clues as to what happened, this was awesome! My main PC started randomly hard locking today for no reason so I wonder if this will catch anything...
@sirius4k
@sirius4k 2 жыл бұрын
That was Wendell in your PC.
@JoriDiculous
@JoriDiculous 2 жыл бұрын
Mine been doing that for years. Event Viewer only give the most helpful hint: "The system has rebooted without cleanly shutting down first. " The rest of the logs gives no clue what so ever.
@webtax
@webtax 2 жыл бұрын
I blame recent systems. My oc'd sandy would run error free for years, bought alder lake, already had a hard freeze after a month, stock. Ryzen also has issues.
@WestOfAsh
@WestOfAsh 2 жыл бұрын
I love the team at Level1Techs, Wendell is great thoroughly helpful/knowledgeable, Kreestuh is skillful with design and her drawing on iPad reviews are incredible, Ryan with his sarcasm and dry humor gets me every time! Thank you everyone for all you do! I am happy to consume your videos anytime.
@rjjeffreys
@rjjeffreys 2 жыл бұрын
Always an excellent learning experience watching your videos! I have battled the EV dragon for decades, and am looking forward to using Sysmon on a deeper level in this approach to debugging the relentless EV error logs.
@TubularAnde
@TubularAnde 2 жыл бұрын
Good video! I've been troubleshooting a memory overclock (most of the problems stemming from a motherboard BIOS with questionable UX), and had to set up a custom view in event viewer to find WHEA errors. I've used other Sysinternals programs before but Sysmon never occurred to me. Thanks for the tip!
@ericbouchard3995
@ericbouchard3995 2 жыл бұрын
Thanks for making me check my event logs. I had over 50000 entries about an NVIDIA service that couldn't start.
@brutuz_prime
@brutuz_prime 2 жыл бұрын
I was totally fooled into checking my e-mail by the alert sound at 8:49
@arnox4554
@arnox4554 2 жыл бұрын
The Event Viewer has been both really useful to me and also really useless sometimes too. Or maybe sometimes an event I'm interested in will show up in the Event Viewer but have almost if not completely useless information about it. Linux doesn't have these logging issues whatsoever. If there's a problem anywhere at ALL, it will be in the logs in some form and it will be thorough enough to diagnose issues, but not so thorough as to be filled with overly obtuse technical jargon. (95% of the time anyway.)
@SubUrDie
@SubUrDie 2 жыл бұрын
Prefect timing for this video. Been trying to troubleshooting AMD Driver issues with amdwddmg warning and Live Kernel Event 141 errors
@christopherjackson2157
@christopherjackson2157 2 жыл бұрын
There's something real weird with the current amd drivers and the way it interacts with the tpm. Hard to tell if it's a bug or a bandaid solution for some other deeper bug lol
@jairo8746
@jairo8746 2 жыл бұрын
@@christopherjackson2157 Not drivers, but BIOS issues, AMD said that they were going to release a new version that fixes those issues with TPM, i don't know if it is live yet though.
@christopherjackson2157
@christopherjackson2157 2 жыл бұрын
@@jairo8746 the amd website says it'll be live may 22
2 жыл бұрын
Fue increíble vivirlo arriba del escenario, participar como cámara y editar esto. Muy muy agradecido. Felicitaciones a los pibes, staff, nuestro equipo de Zelaya y a Farolatino. Histórico!
@teck_nically_4069
@teck_nically_4069 2 жыл бұрын
Thanks for this, lot more I can look into issues at work with this
@brayansamboni685
@brayansamboni685 2 жыл бұрын
A really very clear and accessible review of the bot turned out!!!
@classycanadian
@classycanadian 2 жыл бұрын
Please upload more content about diagnosing BSOD with the Event Viewer!
@Snail3r
@Snail3r 2 жыл бұрын
Yes please do.
@katarjin
@katarjin 2 жыл бұрын
Fitting that I see this video after trying to figure out why Windows failover was borked at work and the Event logs were..less that helpful. (SwiftOnSecurity is a great person to follow for bits of IT knowledge ...and memes.)
@Nobody-vr5nl
@Nobody-vr5nl 2 жыл бұрын
Event viewer is amazing. When I was working as a POS tech, I used it on A LOT of service calls. Used it for personal use when errors or games crash
@darylg3560
@darylg3560 2 жыл бұрын
You know it's gonna be a good video when ever Mr Russinovich shares it on Twitter! Learnt a lot, thank you!
@realdomdom
@realdomdom 2 жыл бұрын
You can also make a custom trigger event for a service by listening to an event, like process creation for example, to make a service start when a certain program starts.
@Fruhmple
@Fruhmple 2 жыл бұрын
This is very useful, thank you. I'd love to see a video like this on Linux.
@conan1231
@conan1231 6 ай бұрын
Can someone elaborate how I can send my Windows Events from a Windows 10 Pro to my Linux Syslog Server without an third party agent? The Windows Event Forwarder only works for sending the logs to another Windows Client..
@cepi24
@cepi24 2 жыл бұрын
Where is the video about the blue screen mentioned in in cca 2nd minute? Thanx
@krwhynot
@krwhynot 2 жыл бұрын
great info!
@ChuckNorris-lf6vo
@ChuckNorris-lf6vo 2 жыл бұрын
Yessss more content like this!!! ❤️
@lovemys65amg19
@lovemys65amg19 2 жыл бұрын
THANK YOU SO MUCH
@djvidual8288
@djvidual8288 2 жыл бұрын
I have some instability currently and the vanilla Windows Event Log doesn't give me the information I need. The Sysmon will come in very handy. Thanks a lot!
@aprilmeowmeow
@aprilmeowmeow Жыл бұрын
you're a very good teacher :)
@chromefinch
@chromefinch 2 жыл бұрын
This, this is why i come here. Do more stuff like this. Let's set up our log server. What do you recommend for open source logging solutions?
@TrevorReimer
@TrevorReimer 2 жыл бұрын
I know you said don't send event logs to a syslog system but I still would like to try using it with the GrayLog Illuminate Package. Too bad it's an enterprise only feature not in the community edition of GrayLog
@leviathanpriim3951
@leviathanpriim3951 2 жыл бұрын
Thanks Wendell
@brianwest7344
@brianwest7344 2 жыл бұрын
Every time I open something it gives me a code, I look the code up and it's usually a general error code with no description of what can cause it
@TheStevenWhiting
@TheStevenWhiting 2 жыл бұрын
Thanks to Mark Russinovich for linking to this. The best guide for the sysmon config I've found.
@alandjhdz
@alandjhdz 2 жыл бұрын
Thank you  sir
@-Good4Y0u
@-Good4Y0u 2 жыл бұрын
this is a great video.
@thelegalsystem
@thelegalsystem 2 жыл бұрын
I am very experienced with the Windows Event Log because of the headache that is USB
@rexxar7227
@rexxar7227 2 жыл бұрын
"View Reliability history" is another great tool to keep in your toolbox for windows diagnostics.
@treyquattro
@treyquattro 2 жыл бұрын
Mark is, to reference a famous yet apt quote, a righteous dude.
@itsdeonlol
@itsdeonlol 2 жыл бұрын
I always use the Event Viewer! It saved my PC a lot of times when my system was acting up!!! I recommend everyone use the Event Viewer!!!
@TheStevenWhiting
@TheStevenWhiting 2 жыл бұрын
I've read once you've got a config.xml file you're happy with, once loaded you should delete it as anyone that gets on will look for a config file if they see sysmon to see what you're logging.
@wskinnyodden
@wskinnyodden 2 жыл бұрын
Yeap, sysinternals tools are AWESOME!
@xerox445
@xerox445 2 жыл бұрын
The outlook dings get me so screwed up lol
@ashgupta326
@ashgupta326 2 жыл бұрын
This is cool it worked thxGuys it really works, I checked.
@peterjansen4826
@peterjansen4826 2 жыл бұрын
A video like this for Linux-users would be interesting.
@3isr3g3n
@3isr3g3n Жыл бұрын
I'm seriously considering building an altar to Wendell, i've learned so much stuff from him that i use everyday
@Simonthadude
@Simonthadude 2 жыл бұрын
Tack!
@hypolyxa7207
@hypolyxa7207 2 жыл бұрын
SVERIGE
@Level1Techs
@Level1Techs 2 жыл бұрын
thank you!
@taiiat0
@taiiat0 2 жыл бұрын
yep, the built in Logging is pretty good.
@jb34304
@jb34304 2 жыл бұрын
Speaking of GeForce Experience: Would you recommend people use the programs _NvSlimmer_ or _NVCleanstall_ to get rid of the Nvidia bloatware? I personally use Slimmer, as it installs a signed driver. And both do a decent job of explaining what you are removing from the driver pack.
@ObscenePizza
@ObscenePizza 2 жыл бұрын
How did you manage to comment 7 days ago on a video that has been posted only 1 hour ago (according to KZbin). I'm confused. Back on topic; NVCleanstall also allows you to rebuild the digital signature now, but I'm not sure if the method differs.
@fadinrenegade
@fadinrenegade 2 жыл бұрын
@@ObscenePizza Patreon supporters get early access to videos.
@jb34304
@jb34304 2 жыл бұрын
@@ObscenePizza @ObscenePizza @ObscenePizza How can I comment on a video that isn't public? It's the power of omnipresence 😇 . No I'm just joking, I am a Patreon member, and one of the benefits is seeing some of their content posted early. Thanks for responding to my question. I really appreciate it. Never spoken to someone who wasn't from the U.S. on here. It'd be nice to hear from Wendell about this one, as I feel it's something worth investigating thoroughly. The rest is more or less a rant you don't have to read... The example I speak of is removing specific aspects of the driver package, and if it's more of a hindrance than a benefit. Will tearing apart the drivers cause our computers to operate suboptimally/introduce instability while using 3D applications? A lot of streamers have traded in OBS for Geforce Experience, and I don't understand why. Even my Maxwell series Titan X (7 years old now) supports the newest NvEn Hardware encoding to either 2K @ 60 FPS , or 4K @ 30 fps without significant impacts to performance. When GeForce Experience was bundled with the display driver, and initially there wasn't a choice to install _the display driver only._ I swore off any drivers that contained it/telemetry. Finding those programs was a godsend imho.
@hockeylad2727
@hockeylad2727 2 жыл бұрын
I mean Wendell that's why you run a RD Gateway and log everything with a Directory system ;)
@viruslab1
@viruslab1 2 жыл бұрын
Very handy tool, thank you for good info!
@papijelly
@papijelly 11 ай бұрын
Me watching this video today is IRONIC. For the first time in over 10 years of being in the field I plugged in an USB thumbdrive and it blue screened my desktop. haha
@ObscenePizza
@ObscenePizza 2 жыл бұрын
Wish there was a decent integration with Home Assistant.
@SwedishDeathLlama
@SwedishDeathLlama 2 жыл бұрын
Proceed with caution, the sysmon driver often failed to load/unload properly causing windows to hang at shutdown and startup unpredictably in our environment.
@kennethhicks2113
@kennethhicks2113 2 жыл бұрын
Yea, EV is and has been a great tool. You can organize it and it's easy to find issues quick (mostly... Win lol)
@nathantron
@nathantron 2 жыл бұрын
oddly convenient... I've been having serious issues with Windows 10 becoming completely unfunctional when network drives are not available to it... Somehow the entire OS becomes unstable as fuck. Copy paste is broken, search is broken, rendering of the explorer window is glitchy and corrupt.. more than 400 instances of services. it's insane.... When you reboot and the computer as access to those drives again, it's all fine and dandy again..
@superslammer
@superslammer 2 жыл бұрын
This absolutely needs a gui :)
@WaRn00b85
@WaRn00b85 3 ай бұрын
CORRECTION: Sysmon isn't "From MS", and is a SysInternals tool, AND ISN'T OFFICIALLY supported by MS - If you have an issue on an enterprise server, and they find it's Sysmon related, they will close the support case as Sysmon isn't supported.
@doxydoxdelamanca9902
@doxydoxdelamanca9902 2 жыл бұрын
emphasis on "if you can reAD! and have a pulse!"
@dawbra
@dawbra 2 жыл бұрын
I have "lovely" mouse that when i plug it on it blue screen my system , i need to plug it on a first boot being in bios to make it safe , and work after a post xD
@finelliott2440
@finelliott2440 2 жыл бұрын
Event Viewer is a headache IMO
@dwytcodm6767
@dwytcodm6767 2 жыл бұрын
Theres so many of them that only use walls.. they think if they still
@TheStevenWhiting
@TheStevenWhiting 2 жыл бұрын
You wanna do sysmon64 -accepteula if doing this remote so the eula is accepted. Stupid lawyers. I do sysmon64.exe -accepteula -i nameofconfig.xml
@btschaegg
@btschaegg 2 жыл бұрын
Wait, what? The EventViewer is *overwhelming* ? Did I switch dimensions or something? The Tool (not the content) is massively *underwhelming* to me. Seriously, that thing was badly designed even for the 90ies. Also: How the hell can this thing still look like in Win95 *and* still take like 20 Seconds to show useful content after the first start on modern hardware that's literally *orders of magnitude* faster? Edit: I have to agree with the description of Sysmon, though. I'm pretty sure "that should just be shipped with Windows" is basically the SysInternals tagline. Literally every one of Russinovich's tools is drastically better than the built-in alternatives.
@TheStevenWhiting
@TheStevenWhiting 2 жыл бұрын
The last bit about shipping with windows. Yes but if it was shipped with Windows it wouldn't be allowed to be updated as frequently as it is so its better that all the tools are never shipped with Windows.
@C_C-
@C_C- 2 жыл бұрын
sysinternals stuff was all borderline rootkit, horrible security risks in enterprise, procmon has some unique uses
@alexbold4611
@alexbold4611 2 жыл бұрын
Everything you run in windows as administrator is essentially a root kit, but who cares… Did you know someone who create users without admin rights and typing admin password every time, I don’t
@ShEmDK
@ShEmDK 2 жыл бұрын
@@alexbold4611 Now you do... 😋
@ardas77
@ardas77 2 жыл бұрын
Oh hai.
@ole7736
@ole7736 2 жыл бұрын
Wendell, let me help you with making videos. Please. I sometimes lose my patience a little bit. ;) When you start talking about a thing ("Let me introduce you to Sysmon"), PLEASE let the very next sentence be a very concise one about what this thing is. Don't take 5-10 sentences of "suspension" where you let the viewer/listener figure this out on their own. You could even start the whole video with "This video is about Sysmon. Sysmon is a piece of software that lets you customize/filter the Windows event log. To understand this you need to know about the Windows event log. So let me introduce you to this first." Imagine that! Straight forward, simple, easy to understand. :) Also please only show b-roll footage if it is illustrating what you are talking about right at that moment! Don't repeat footage while you are talking about something different, just to show something at all. Because then the viewer is busy trying to figure out in what relationship the footage is to what you are talking about, getting confused in the process. Let everything you show be in a clear and direct relationship to what you are talking about right in that moment. And if you are talking about digging deeper when trying to figure out which drive is throwing errors, either show the process of figuring this out all the way or don't show it at all. Don't just show it half the way. You are leaving the user mentally busy while you return to the actual topic.
@Jagerbomber
@Jagerbomber 2 жыл бұрын
Event Viewer isn't USUALLY helpful in figuring out WHY specific games (or a specific game) are crashing if it is actually just their own issue, right?... Or something you probably can't solve.
@Level1Techs
@Level1Techs 2 жыл бұрын
Sysmon will help with that though and let you log more useful stuff.
@JoriDiculous
@JoriDiculous 2 жыл бұрын
Even viewer is almost useless (in its basic forms). Only filled nonsense and thousands of Distributed COM. I had forgot i installed this config a couple of years ago. Boy have the xml changed :)
@Level1Techs
@Level1Techs 2 жыл бұрын
hence, watch the video, and make it less useless with sysmon?
@JoriDiculous
@JoriDiculous 2 жыл бұрын
@@Level1Techs Its still a lot to scroll Through, but at least it makes a bit more sense. Hope it catches hardware error better
@TechySpeaking
@TechySpeaking 2 жыл бұрын
first
@gabest4
@gabest4 2 жыл бұрын
Windows has a message center now. They should just dump every event there! Warnings and errors. Probably a simple 3rd party service could do it, too.
@ethix_ru
@ethix_ru 2 жыл бұрын
6:04 6:37 stupid Powershell :D
@smoshGaming
@smoshGaming 2 жыл бұрын
Thanks to all the complaining about $400 pans in the news I just got an ad for a $400 pan.
@nemesis851_
@nemesis851_ 2 жыл бұрын
Ding 🛎 Ding 🛎 Windows will restart in 60 seconds (ignoring “pause updates”, unable to permanently full stop updates)
Level1 Diagnostic: Why Is 128 Cores So Janky On Windows?
27:57
Level1Techs
Рет қаралды 69 М.
Icy Dock Ramble For the Ultimate Home Server
19:32
Level1Techs
Рет қаралды 78 М.
路飞太过分了,自己游泳。#海贼王#路飞
00:28
路飞与唐舞桐
Рет қаралды 29 МЛН
ПРОВЕРИЛ АРБУЗЫ #shorts
00:34
Паша Осадчий
Рет қаралды 7 МЛН
Amazing weight loss transformation !! 😱😱
00:24
Tibo InShape
Рет қаралды 60 МЛН
How to tell if your PC is Hacked? Process Forensics
8:57
The PC Security Channel
Рет қаралды 494 М.
Pass on LastPass; KeepassXC or Bitwarden is better.
13:42
Level1Techs
Рет қаралды 171 М.
Level1 Presents: THE FORBIDDEN ROUTER II - DIAL-UP BY DAWN
18:49
Level1Techs
Рет қаралды 48 М.
Hardware Raid is Dead and is a Bad Idea in 2022
22:19
Level1Techs
Рет қаралды 666 М.
Windows 11 24H2 is Going To Be A Huge Update!!
22:44
CyberCPU Tech
Рет қаралды 297 М.
Level1 Presents: THE FORBIDDEN ROUTER
16:38
Level1Techs
Рет қаралды 141 М.
NEVER install these programs on your PC... EVER!!!
19:26
JayzTwoCents
Рет қаралды 3 МЛН
HAProxy-WI: Run Lots Of Public Services On Your Home Server
25:24
12 GREAT command line programs YOU recommended!
16:25
The Linux Experiment
Рет қаралды 244 М.
Windows Event and Logging Demystified: IT Admin Edition
36:38
TechsavvyProductions
Рет қаралды 14 М.
Здесь упор в процессор
18:02
Рома, Просто Рома
Рет қаралды 430 М.
iPhone 16 с инновационным аккумулятором
0:45
ÉЖИ АКСЁНОВ
Рет қаралды 10 МЛН