Hello,
while testing in our system I noticed that PowerShell and Sysmon events are not arriving in the SIEM system. Other events such as Windows Event ID 4624 arrive without any problems. The template is defined for the PowerShell events Microsoft-Windows-PowerShell/Operational and Windows PowerShell. The local security guidelines are also set. I'm using Windows Agent 7.2.2. What am I doing wrong?
Best Regards
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
If anyone has a similar problem. The update to WindowsAgent 7.2.4 has helped...
If anyone has a similar problem. The update to WindowsAgent 7.2.4 has helped...
Welcome to your new Fortinet Community!
You'll find your previous forum posts under "Forums"
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.