Skip to main content
sehran
New Member
January 17, 2025
Question

Assistance Required in Identifying Logs for Patched Vulnerabilities

  • January 17, 2025
  • 2 replies
  • 1298 views

We are using FortiClient with EMS and FAZ integrated to manage and monitor endpoint security. Recently, EMS detected a vulnerability in Google Chrome on one of the endpoints. The user subsequently patched the vulnerability by updating Chrome to the latest version (e.g., version X.X.X).

However, I am unable to find any logs that indicate:

  1. The patching action: A record of the software being updated or the vulnerability being patched.
  2. Version information: Logs reflecting the software version before and after the update.

Despite reviewing logs in both EMS and FAZ, I could not identify relevant entries indicating the patching or update process.

Request for Support:

  1. Could you confirm if such events are logged by FortiClient and forwarded to EMS and FAZ?
  2. If yes, what log fields, indicators, or keywords (e.g., event type, status, or version details) should I search for in EMS and FAZ logs?
  3. Are there any specific configurations needed in FortiClient, EMS, or FAZ to ensure that logs for software updates and patched vulnerabilities are generated and visible?

2 replies

Anthony_E
Staff
Staff
January 20, 2025

Hello,


Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.


Thanks,

Best Regards
AEK
SuperUser
SuperUser
January 23, 2025