Hi guys
I'm experiencing this kind of issue with FortiSIEM agent on Windows 2022 Server, the agent is not able to send logs related to Sysmon or any other kind of logs, even with different windows agent template associations.
When SNMP is configured to send info, the Supervisor is able to show this on performance and analytic real-time dashboards, but when the filter is like "Event type NOT CONTAIN PH", I can't see any logs, is supposed to be the event, system events, etc...
The CMDB show the server with agent status "Running active", the method "snmp, agent, ping", so no connectivity problem here.
How can I get some tips to solve this??
Thank you!
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
I updated the agent to 7.1.1 version and it solved everything.
Thank you!
Hi,
You created a Windows Agent template and added the relevant host into that template, right?
Hi @adem_netsys , thank you for your reply. Yes, I linked the host as the GUI suggest this step and then applied the settings at the end.
When no template is associated with the host, the CMDB agent status is "Registered". In this case, the state shows "Running active"
Created on 12-05-2023 05:47 AM Edited on 12-05-2023 05:49 AM
Can you see the policy name on CMDB and if you are using tenant structure, you may need to search on the tenant you are on.
Yes, its shows the policy before the status "running active".
Analytics either from super view or direct tenant view only show PH logs from snmp.
Hi
Maybe a couple of things to check.
I hope that helps!
Hello @Richie_C
1. From super, I guess. Because credentials were added there and snmp discovery was done from super. (server is allowed to send traps to collector & super)
2. tcpdump from collector shows snmp notifications from the windows server, from super tcpdump show other kind of trafic (https related)
3. I followed this topic about sysmon: https://community.fortinet.com/t5/FortiSIEM/Technical-Tip-Configure-Sysmon-with-Windows-Agent/ta-p/1...
You say this: Is the correct auditing configured on server?
Eventviewer.msc show a plenty of logs from Security, System, DNS, ... the template agent relate this events and were applied to the host. What am I missing on this step?
Thank you!
Hi
Could you share a screenshot of the agent template. This will help me to understand the event you are trying to collect.
Thanks
Richard
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1547 | |
1031 | |
749 | |
443 | |
210 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.