Best Practice: Recommended Parsers for Windows and Linux Devices in FortiSIEM
Hi everyone,
I'd like to better understand, from a real-world operational perspective, which parsers you consider essential/recommended for Windows and Linux devices in FortiSIEM (7.4.x / 7.5.x), especially considering:
-
Better security visibility
-
Reduction of unnecessary logs
-
Storage optimization
-
Environment performance
-
Better cost-benefit of event ingestion
We are currently reviewing the parsers enabled across our environments and noticed that many deployments tend to enable too many parsers, generating a huge amount of events with limited operational value.
Today, we are using something similar to the following:
Windows:
-
WinDHCPParser
-
WinDNSParser
-
WinDefATPParser
-
OSQueryWindowsParser
Linux:
-
SyslogNGParser
-
LinuxDHCPParser
-
LinuxInotifyParser
-
LinuxAuditdParser
-
UnixParser
I’d like to hear from the community:
-
Which parsers do you consider indispensable for Windows environments?
-
Which parsers truly add value for Linux servers?
-
Are there any parsers you usually avoid because they generate excessive noise or low-value logs?
-
How do you balance visibility vs. storage/EPS consumption?
-
Do you deploy Auditd / Sysmon / OSQuery on every server or only on critical assets?
-
Is there any official Fortinet best practice for parser hardening or optimization?
If possible, please share real-world experiences from MSSP/SOC environments, including:
-
EPS reduction strategies
-
Storage optimization
-
Parser tuning
-
High-value use cases
-
Lessons learned after production deployments
Thank you!