Event ID 4: Sysmon service state changed
Contents
Event ID 4: Sysmon service state changed¶
Version: 4.81¶
Description¶
The service state change event reports the state of the Sysmon service (started or stopped).
Data Dictionary¶
Field Name |
Type |
Description |
Sample Value |
---|---|---|---|
UtcTime |
date |
Time in UTC when event was created |
|
State |
string |
sysmon service state (i.e. stopped) |
|
Version |
string |
sysmon version |
|
SchemaVersion |
string |
sysmon config schema version |
|