I find the sysmon config files confusing and not enough clear info on creating them. So having issues finding out if this is possible or not.
I'd like to ignore most logs sysmon can do and just use it to monitor one specific folder and one specific AD user that accesses said folder.
Is this possible and what would the config file look like if so?
