Skip to main content
gauravpawar
Explorer III
February 10, 2026
Question

Issue Fetching .sqlaudit Logs Using Windows Agent User Log Template

  • February 10, 2026
  • 2 replies
  • 152 views

The customer stores .sqlaudit logs on the C:\ drive of a Windows machine where the Windows Agent is installed. Multiple log files are continuously updated, and once a file reaches its size threshold, a new .sqlaudit file is created.

The customer wants to collect logs from all generated files, including their contents. They attempted to use Windows Agent Template → User Log, but the logs are not being fetched.

Could someone please assist with this issue?

2 replies

gauravpawar
Explorer III
February 11, 2026

@Anthony_E  @Secusaurus could you please help here ?

Anthony_E
Staff
Staff
February 11, 2026

i invite you to post in the FortiSIEM discussion instead of the general one.

Best Regards