Skip to main content
Question

Injesting sysmon logs via Elastic API and events are getting dropped

  • March 11, 2025
  • 1 reply
  • 5 views

Hi, I am trying to ingest sysmon logs via the Elastic api. But i do not see any live data but instead i get all dropped counts. Can anyone help?

1 reply

Hey @Joel Yue I just want to be sure I am understanding your use case. Are you using the Elasticsearch API (Source) to pull sysmon logs from Elasticsearch and you aren't observing any data?

If the aforementioned is correct, can you provide a sanitized version of the input/source config here and any error logs?