Then, what kind of logon eventID is generated by your Active directory?
Try to create logon event and run commands above again.
Also, where is your screenshoot with shown logged on user? In your debug outputs, there is no logged on users at all.
FortiGate (FGT) has an integrated poller as well. Its local polling mode also uses the Windows Security Event logs, however currently the supported event subset is smaller.
• Windows 2008/2012/2016/2019 Event IDs: 4768, 4769, 4776
• Windows 2003 Event IDs: 672, 673
_____________________
https://community.fortinet.com/t5/FortiAuthenticator/Technical-Tip-Windows-event-IDs-used-by-FSSO-in-WinSec-polling/ta-p/189910