Install Sysmon using Microsoft Intune
CAUTION: Arctic Wolf does not recommend upgrading to Sysmon version 15.20 due to a compatibility issue with the Arctic Wolf Agent. A fix will be released with Agent version 2026-01+.
You can install Sysmon on multiple Windows endpoints using Microsoft Intune® and Sysmon Assistant.
When Sysmon is installed on a device:
- The Arctic Wolf configuration is applied and set by default when Arctic Wolf Agent and Sysmon are installed on a device without a previous Sysmon configuration. If a different configuration already exists, it will not be overwritten.
- The installation method does not affect how the Arctic Wolf Agent interacts with Sysmon.
- The location of Sysmon.exe does not change the behavior of Sysmon on the system because it runs as a service and a separate driver.
- Sysmon events are forwarded to Arctic Wolf regardless of the Sysmon installation method and configuration. But, the Arctic Wolf pipeline is optimized to work with Arctic Wolf configurations. If you use your own configuration, some events might not be alerted on.
These resources are required:
- Arctic Wolf®Agent
See Install Arctic Wolf Agent for more information.
- One of these operating systems (OS):
- Windows 10 or newer for 64- and 32-bit systems
- Windows Server 2016 or newer for 64-bit systems
Note: Agent OS minimum requirements are different from Sysmon minimum OS requirements. If you are installing Sysmon, make sure that you are installing the appropriate version for your OS. For older operating systems that Agent supports but Sysmon does not, we recommend that you upgrade to a current version of the OS. Arctic Wolf cannot support you with any configuration issues for older versions of Sysmon.
These actions are required:
- Download the Sysmon.zip file for the latest Sysmon version, which includes the executable files, from the Microsoft website.
- If you want to use Sysmon Assistant to install Sysmon, in the Arctic Wolf Unified Portal, click , go to the Sysmon section, and then click Download Assistant to download the SysmonAssistant.zip file.
- Extract Sysmon.zip and SysmonAssistant.zip and save these Sysmon Assistant installation files in the same folder.