FortiSIEM Discussions
adem_netsys
Contributor II

Some Windows Security Logs Issue with Windows Agent

Hi guys,

 

We're facing a problem. We are getting Windows logs with Windows Agent, but we are getting some logs and not getting some logs. For example, we cannot get some of the MSSQLServer33205 logs and some of them, in addition, we cannot see the log with ID 1104 in Events. What can we do for this? Agent Version 7.2.5.

 

Thanks in advance

1 REPLY 1
cdurkin_FTNT
Staff
Staff

Probably best bet would be to you look in detail on the windows side at what the "EventRecordID" is for the missing entries .. you can view this under Details/Friendly View in the Windows Event Viewer.

eventRecordID.png

Then you can search for the corresponding ID in FortiSIEM...

eventRecordID_FSM.png

By either a Keyword Search... or by searching Reporting IP = x.x.x.x and Sequence Number = <ID>

If you do in fact have missing entries, then I would suggest a TAC ticket.