Sysmon Log Collection

NOTE - Windows event log collection channels

Windows event logs are collected from the following channels:

  • Application
  • System
  • Security

All entries in these channels are collected, and it is not customizable at this time.

https://docs.rapid7.com/insightidr/configure-the-insight-agent-to-send-logs/