Loading

Sysmon for Linux Integration

<div class="condensed-table">
| | |
| --- | --- |
| Version | 1.7.2 (View all) |
| Compatible Kibana version(s) | 8.4.0 or higher |
| Supported Serverless project types
What’s this? | Security
Observability |
| Subscription level
What’s this? | Basic |
| Level of support
What’s this? | Elastic |

</div>
The Sysmon for Linux integration allows you to monitor the Sysmon for Linux, which is an open-source system monitor tool developed to collect security events from Linux environments.

Use the Sysmon for Linux integration to collect logs from linux machine which has sysmon tool running. Then visualize that data in Kibana, create alerts to notify you if something goes wrong, and reference data when troubleshooting an issue.

Note

To collect Sysmon events from Windows event log, use Windows sysmon_operational data stream instead.

You need Elasticsearch for storing and searching your data and Kibana for visualizing and managing it. You can use our hosted Elasticsearch Service on Elastic Cloud, which is recommended, or self-manage the Elastic Stack on your own hardware.

For step-by-step instructions on how to set up an integration, see the Getting started guide.

The Sysmon for Linux log data stream provides events from logs produced by Sysmon tool running on Linux machine.