You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
I've noticed that the base config everything gets merged into is still on 4.60 but the latest I saw on the Sysmon release notes a couple point releases ago (I believe 13.32) is 4.81. There are new syntax conditionals introduced in 13.3x such as not begin with and not end with that are utilized in 4.81.
Are there plans to update the base schema version soon?
PS
Thanks for the help with making Sysmon configs more manageable!
The text was updated successfully, but these errors were encountered:
Well yes, once I have a need for those new fields I'll update the schema. Since Sysmon is backwards compatible there is no need to update it as of now. This also allows people on earlier versions to still benefit from it
Hi,
I've noticed that the base config everything gets merged into is still on 4.60 but the latest I saw on the Sysmon release notes a couple point releases ago (I believe 13.32) is 4.81. There are new syntax conditionals introduced in 13.3x such as
not begin with
andnot end with
that are utilized in 4.81.Are there plans to update the base schema version soon?
PS
Thanks for the help with making Sysmon configs more manageable!
The text was updated successfully, but these errors were encountered: