Event ID 16 - Sysmon Config State Changed
Contents
Event ID 16 - Sysmon Config State Changed¶
Version: 4.81¶
Description¶
This event logs when the local sysmon configuration is updated.
Data Dictionary¶
Field Name |
Type |
Description |
Sample Value |
---|---|---|---|
UtcTime |
date |
Time in UTC when event was created |
|
Configuration |
string |
name of the sysmon config file being updated |
|
ConfigurationFileHash |
string |
hash (SHA1) of the sysmon config file being updated |
`` |