Hello!
I'm unable to query 'Microsoft-Windows-Sysmon/Operational' windows event log when running sheduled or live distributed queries from fleetdm server, the output is null with no errors in logs. When I run the same query directly on the machine - it's working as expected. Could you, please, tell me what can I do to investigate the problem?