Hello everybody, For testing purpose, we use Solarwinds Log Forwarder in order to send Windows events via syslog to our Fortianalyzer. Those particular messages seem to be truncated in "Log View" (first line only) With another syslog server the messages are OK. Here is an example of a message sent by Log Forwarder : "01-25-2018 11:13:09 Kernel.Notice 127.0.0.1 janv. 25 11:13:09 ********** MSWinEventLog 5 Security 267 jeu. janv. 25 11:12:59 2018 4776 Microsoft-Windows-Security-Auditing N/A Audit Success ********** 14336 L’ordinateur a tenté de valider les informations d’identification d’un compte. Package d’authentification : MICROSOFT_AUTHENTICATION_PACKAGE_V1_0 Compte d’ouverture de session : ********** Station de travail source : ********** Code d’erreur : 0x0" Here is the result in FortiAnalyzer (first line only) : 01-25-2018 11:13:09 Kernel.Notice ********** janv. 25 11:13:09 ********** MSWinEventLog 5 Security 267 jeu. janv. 25 11:12:59 2018 4776 Microsoft-Windows-Security-Auditing N/A Audit Success ********** 14336 L’ordinateur a tenté de valider les informations d’identification d’un compte. Is there a maximum message size with Fortianalyzer or prohibited characters (such as line feed etc.) ?
P.S : sorry for my broken english, french dude here
User | Count |
---|---|
2037 | |
1169 | |
770 | |
448 | |
333 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.