Hello,
I am running an AD on Windows Server 2019, and I would like Fortisiem to trigger any change or modification made on the DNS server ( adding a new record, deleting a record, etc ... ).
Fortisiem now polls event information from different DCs by using OMI.
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
There are two approaches for this... for your investigation
(1) Collect the DNS Audit Log: (Requires FortiSIEM Windows Agent)
https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/d...)
Monitor the Specific DNS Auditing Event Log: Microsoft-Windows-DNSServer/Audit
(2) Native OS Logging: (Via Security Event Log, ok for OMI)
https://techcommunity.microsoft.com/t5/core-infrastructure-and-security/who-moved-the-dns-cheese-aud...
(1) is the best approach, (2) will generate lots of events as a FYI..
There are two approaches for this... for your investigation
(1) Collect the DNS Audit Log: (Requires FortiSIEM Windows Agent)
https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/d...)
Monitor the Specific DNS Auditing Event Log: Microsoft-Windows-DNSServer/Audit
(2) Native OS Logging: (Via Security Event Log, ok for OMI)
https://techcommunity.microsoft.com/t5/core-infrastructure-and-security/who-moved-the-dns-cheese-aud...
(1) is the best approach, (2) will generate lots of events as a FYI..
Thank you for your feedback, I can appreciate more
Welcome to your new Fortinet Community!
You'll find your previous forum posts under "Forums"
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.