Technical Tip: How to configure Agent Template -> User Log
| Description | This article describes how to configure the User Log in a Windows template configuration. |
| Scope | FortiSIEM, Windows Agent. |
| Solution |
Reporting IP = <Host_IP> Raw Event Log CONTAIN AO-WUA-UserFile
Note: If the monitoring file doesn't create new log lines while monitoring, no events will show up in Analytic. To test, open the file, copy some lines that contain the prefix and paste them at the end of the file -> Save. Run the Analytic Query again.
In version 7.4.0, multiple-line features have been added.
If the log is divided into multiple lines, the start and end of the log can be indicated (Regular Expression supported), and the number of lines can be specified. See the User Guide -> Configuring Windowd Agent Guide link for more information: Configuring Windows Agent. |





