I have installed sysmon 7.03 and I faced this same issue. I managed to install sysmon with GP and added the command to change the permissions to the batch file, but I'm not sure why it takes long time for the events to show up in the collector. I have applications events that are being collected from all my workstations and they show up really quick in the collector but sysmons events always are behind like 30-40 mins... I used the default refresh time=900. Im not sure if this might be the issue here, also I'm filtering the sysmon events to only forward when I open an application, could this be the issue here? here is the xpath filter that I'm using:
<Query Id="0" Path="Microsoft-Windows-Sysmon/Operational">
<Suppress Path="Microsoft-Windows-Sysmon/Operational"> *[EventData[Data[@Name='CurrentDirectory'] = 'C:\Windows\CCM\']] or *[EventData[(Data[@Name='LogonId'] = '0x3e7' or Data[@Name='LogonId'] = '0x3e4' or Data[@Name='LogonId'] = '0x3e5')]] or *[EventData[Data[@Name='ParentImage'] = 'C:\Windows\System32\svchost.exe']]
I used the Custom view in my workstation to test and it works... but I'm new to xpath or xml, and I'm not sure if this filter is configure correctly.