System32
Sysmon
Events
Compliance
Validator
TLS/SSL
GeoIP
Tools
Sysmon Events
Source
Microsoft-Windows-Sysmon
(1)
Category
Sysmon service state changed
(1)
Tags
AppLocker
All AppLocker events
EventSentry
All EventSentry events
Security
All Windows Security events
Sysmon
All Sysmon events
ID
Event Message
4
Sysmon service state changed: UtcTime: %1!s! State: %2!s! Version: %3!s! SchemaVersion: %4!s!