Hello everybody, For testing purpose, we use Solarwinds Log Forwarder in order to send Windows events via syslog to our Fortianalyzer. Those particular messages seem to be truncated in "Log View" (first line only) With another syslog server the messages are OK. Here is an example of a message sent by Log Forwarder : "01-25-2018 11:13:09 Kernel.Notice 127.0.0.1 janv. 25 11:13:09 ********** MSWinEventLog 5 Security 267 jeu. janv. 25 11:12:59 2018 4776 Microsoft-Windows-Security-Auditing N/A Audit Success ********** 14336 L’ordinateur a tenté de valider les informations d’identification d’un compte. Package d’authentification : MICROSOFT_AUTHENTICATION_PACKAGE_V1_0 Compte d’ouverture de session : ********** Station de travail source : ********** Code d’erreur : 0x0" Here is the result in FortiAnalyzer (first line only) : 01-25-2018 11:13:09 Kernel.Notice ********** janv. 25 11:13:09 ********** MSWinEventLog 5 Security 267 jeu. janv. 25 11:12:59 2018 4776 Microsoft-Windows-Security-Auditing N/A Audit Success ********** 14336 L’ordinateur a tenté de valider les informations d’identification d’un compte. Is there a maximum message size with Fortianalyzer or prohibited characters (such as line feed etc.) ?
P.S : sorry for my broken english, french dude here
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1710 | |
1093 | |
752 | |
446 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.