Hi guys,
I have a windows machine that I would like Active Directory logs to be retrieved as well. Here win agent will be installed. Is the agent enough for this or should I use WMI as I see from the documentation?
Thank you
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi @adem_netsys ,
The below document lists all the logs that agent can send to SIEM:
https://help.fortinet.com/fsiem/7-2-4/Online-Help/HTML5_Help/Configuring_Windows_Agent.htm
If you are looking for logs related to active directory then have to discover via LDAP protocol :
Thanks for the answer, here we can already get the security logs that occur in AD with the agent, is there any situation that affects the logs other than pulling users with LDAP?
Hi Adam,
Normally everything should work uninterruptedly.
This depends on anything unusual on the windows or FortiSIEM super/collector end. Monitor FortiSIEM status via GUI Health and windows by its utilization. Also ensure network connectivity is stable and antivirus doesn't hinder agent communication.
Welcome to your new Fortinet Community!
You'll find your previous forum posts under "Forums"
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.