FortiSIEM Discussions
AliMhaerFathy
New Contributor II

WMI/OMI Integration

Hello,

 

We have followed the WMI/OMI Steps to integrate with FortiSIEM to receive the Security, System, and Application Logs.

we received the Performance logs Only, how we can receive the security logs?

1 REPLY 1
AliMhaerFathy
New Contributor II

I tried this form Supervisor CLI:
/opt/phoenix/bin/omic -s /opt/phoenix/config/smb.conf -U 'User%Password' //IP 'SELECT * FROM Win32_NTLogEvent WHERE Logfile = "Security" AND TimeGenerated >= "20240222000000.000000+000"'

and it retrieved the security logs fine, but the integration couldnt recieve them?