This article describes the issue that FortiGate collector agent 5.0.0.323 or earlier does not support Windows Server 2025 with the default polling mode, which is 'Check Windows Security Event Logs'.
FortiGate collector agent and Windows Server compatibility.
It is common that in the FortiGate collector agent, the default polling mode is used, which is 'Check Windows Security Event Logs'; it works with Windows Server 2022 or earlier.
The version support matrix is listed in the release note below:
FortiGate 7.4.9 Release Notes Product Integration and Support
FortiGate 7.6.4 Release Notes Product Integration and Support
The user will find that once the server is upgraded to Windows Server 2025, the Collector agent query will fail with this default setting.
In such a case, the workaround is to use the 3rd option, 'Check Windows Security Event Logs Using WMI', seen in the screenshot below.
The engineering team is aware of this issue, and a fix is being worked on for the default option to work again.
At this time, the exact date and version of the fix are not available. It will be updated once known.
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.