Hi guys,
We're facing a problem. We are getting Windows logs with Windows Agent, but we are getting some logs and not getting some logs. For example, we cannot get some of the MSSQLServer33205 logs and some of them, in addition, we cannot see the log with ID 1104 in Events. What can we do for this? Agent Version 7.2.5.
Thanks in advance
Probably best bet would be to you look in detail on the windows side at what the "EventRecordID" is for the missing entries .. you can view this under Details/Friendly View in the Windows Event Viewer.
Then you can search for the corresponding ID in FortiSIEM...
By either a Keyword Search... or by searching Reporting IP = x.x.x.x and Sequence Number = <ID>
If you do in fact have missing entries, then I would suggest a TAC ticket.
Welcome to your new Fortinet Community!
You'll find your previous forum posts under "Forums"
User | Count |
---|---|
72 | |
25 | |
15 | |
10 | |
10 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.