I could not find any of the below using the
System Event Category = 2 Query.
Filters: Select the attribute that identifies the Windows Agent heartbeat log. In FortiSIEM’s Event Type browser, find the event type for the agent heartbeat. For example, FortiSIEM categorizes agent heartbeat status under audit events – one common event is “PH_AUDIT_AGENT_RUNNING” (description: Windows/Linux Agent is running and sending events) which the agent sends periodically, and a related event “PH_AUDIT_AGENT_NOTRESPONDING” for when it times outfortinetweb.s3.amazonaws.com. Use the appropriate heartbeat event identifier for your version (e.g. Event Type = PH_AUDIT_AGENT_RUNNING).
Welcome to your new Fortinet Community!
You'll find your previous forum posts under "Forums"
User | Count |
---|---|
72 | |
25 | |
15 | |
10 | |
10 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.