Elastic SIEM + Fleet + Sysmon
Endpoint telemetry pipeline using Sysmon v15+ plus Elastic Agent and Fleet. Validated process, network, and PowerShell events in Kibana Discover and Elastic SIEM.
Artifacts: Endpoint Detection – Elastic SIEM + Sysmon (PDF) · Kibana – Sysmon process events (screenshot)