FortiSIEM Discussions
adem_netsys
Contributor II

Coming Unknown Windows Logs with agent

Hello team,

 

Although policy assignment is made in the windows logs we receive with windows agent, the logs come as ‘unknown’. Has anyone encountered this situation before? We could not solve the problem by adding a device specific parser.

10 REPLIES 10
cdurkin_FTNT

Was TAC successful in helping here?

I'd suggest providing a sample unparsed event.. and look within the sample for the "EventRecordID".

Then on the Windows Device reporting the data .. filter for the same EventRecordID and provide a copy of the XML View (under Details) of the same event.

 

eventRecordID_image.png