Screenshots
Example Usage
# Monitor high network connections from a particular processID Channel=Microsoft-Windows-Sysmon (EventID=3 OR EventID=22) (3=Network Connection, 22=DNS) (DestinationHostname=*.1e100.net OR QueryName=*.gmail.com)