Created on
11-05-2024
04:13 AM
Edited on
10-24-2025
07:34 AM
By
Stephen_G
| Description |
This article describes how to configure the User Log in a Windows template configuration. |
| Scope | FortiSIEM, Windows Agent. |
| Solution |
Reporting IP = <Host_IP> Raw Event Log CONTAIN AO-WUA-UserFile
Note: If the monitoring file doesn't create new log lines while monitoring, no events will show up in Analytic. To test, open the file, copy some lines that contain the prefix and paste them at the end of the file -> Save. Run the Analytic Query again.
In version 7.4.0, multiple-line features have been added.
If the log is divided into multiple lines, the start and end of the log can be indicated (Regular Expression supported), and the number of lines can be specified. See the User Guide -> Configuring Windowd Agent Guide link for more information: Configuring Windows Agent. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2026 Fortinet, Inc. All Rights Reserved.