Cybersecurity Forum

This forum is for all security enthusiasts to discuss Fortinet's latest & evolving technologies and to connect & network with peers in the cybersecurity hemisphere. Share and learn on a broad range of topics like best practices, use cases, integrations and more. For support specific questions/resources, please visit the Support Forum or the Knowledge Base.

isuru
New Contributor II

FortiSIEM - Windows Powershell

Hi,

We are trying to integrate Windows PowerShell logs using the FortiSIEM Windows agent and currently, we have configured Powershell Operational logs. But we have an issue with the given Windows Powershell Event logs where they are not parsing.

We would like to know whether the issue is with our configuration or a parser.

Cheers,
Isuru
Cheers,
Isuru Malawige
Cheers,Isuru Malawige
2 REPLIES 2
FSM_FTNT
Staff
Staff

Hi Isuru,

Do you have any sample events that you can share?

Thanks

Dan
isuru
New Contributor II

Hi Dan,

Please find the Sample Logs herewith.

Cheers,
Isuru
Cheers,
Isuru Malawige
Cheers,Isuru Malawige