Microsoft Sysmon
The subsequent LSO documentation contains detailed information on parsing changes and new log processing settings. The EVID pages show the differences between the old log processing policy (LogRhythm Default) and the new policy to be used with LSO (LogRhythm Default v2.0). Use these pages for reference as you migrate from the old log source type and LogRhythm Default policy to MS Windows Event Logging XML - Sysmon and LogRhythm Default v2.0 policy.