LOGBOOK

HELP

Quiz Entry - updated: 2026.09.24

Where does Sysmon write its events, and which event IDs usually dominate?

Into its own channel, Applications and Services Logs → Microsoft → Windows → Sysmon → Operational, opened with eventvwr.msc. On a normal machine events 1 (process created) and 5 (process terminated) are by far the most common.

Sysmon does not write into the Security or System log. It creates a dedicated channel, Microsoft-Windows-Sysmon/Operational, which makes it easy to collect separately. The same channel name is what a forwarder (Winlogbeat for the Elastic Stack, the Splunk Universal Forwarder) is told to read.

Every Windows process start and stop produces an event 1 and an event 5, so they swamp everything else. That is why a default Sysmon log looks busy but uninformative, and why filtering in the configuration matters: the rare events (a remote thread, LSASS access, a Run-key write) are the ones that matter, and they must not be buried under routine noise.

Go deeper:

From Quiz: ITIA / Logging Lab: Sysmon, Splunk and the Elastic Stack | Updated: Sep 24, 2026