FortiSIEM Discussions
MonXbebe
New Contributor II

Windows Agent, PowerShell Events

Hello,

 

while testing in our system I noticed that PowerShell and Sysmon events are not arriving in the SIEM system. Other events such as Windows Event ID 4624 arrive without any problems. The template is defined for the PowerShell events Microsoft-Windows-PowerShell/Operational and Windows PowerShell. The local security guidelines are also set. I'm using Windows Agent 7.2.2. What am I doing wrong?

 

Best Regards

1 Solution
MonXbebe
New Contributor II

If anyone has a similar problem. The update to WindowsAgent 7.2.4 has helped...

View solution in original post

1 REPLY 1
MonXbebe
New Contributor II

If anyone has a similar problem. The update to WindowsAgent 7.2.4 has helped...

Announcements

Welcome to your new Fortinet Community!

You'll find your previous forum posts under "Forums"