FortiSIEM Parser Matching Issue - Microsoft Exchange Message Tracking and MSSQL Logs
Hi Fortinet Community,
We are experiencing a parser matching issue on FortiSIEM.
Microsoft Exchange Message Tracking logs are collected through Windows Agent user file monitoring. Although MicrosoftExchangeTrackingLogParser exists on FortiSIEM, the incoming Message Tracking logs are always parsed by AOWUA_WinParser.
We tried forcing MicrosoftExchangeTrackingLogParser from CMDB for the related Exchange device. After that, we restarted phparser and performed the killall operations. However, the logs still do not match the expected parser.
We are experiencing a similar issue with MSSQL logs as well. Although the MSSQL parser exists on FortiSIEM, logs coming from the MSSQL server do not match the MSSQL parser.
Could this behavior be related to parser priority, Event Format Recognizer, or the log collection method through Windows Agent?
Has anyone experienced this before or does anyone have any suggestions?
Best Regards,
İsmail ÜREK
