Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
gwaihir
New Contributor III

FortiSiem Agent windows not sending logs to Collector or Super (Only PH_ logs are received SNMP)

Hi guys

 

I'm experiencing this kind of issue with FortiSIEM agent on Windows 2022 Server, the agent is not able to send logs related to Sysmon or any other kind of logs, even with different windows agent template associations.

When SNMP is configured to send info, the Supervisor is able to show this on performance and analytic real-time dashboards, but when the filter is like "Event type  NOT CONTAIN PH", I can't see any logs, is supposed to be the event, system events, etc...

 

The CMDB show the server with agent status "Running active", the method "snmp, agent, ping", so no connectivity problem here.

 

How can I get some tips to solve this?? 

 

Thank you!

1 Solution
gwaihir
New Contributor III

I updated the agent to 7.1.1 version and it solved everything.

 

Thank you!

View solution in original post

17 REPLIES 17
gwaihir
New Contributor III

Hello @Richie_C  this are the screenshots

 

log3.PNGlog2.PNGlog1.PNG

gwaihir
New Contributor III

Of course as I said before, I applied settings when template was assigned.

Richie_C

The FortiSIEM side looks good. What we know so far is:

 

  • Supervisor can communicate with the server
  • We are not seeing port 443 traffic coming into the collector from the server

Based on the above, I would be checking a couple of things:

 

  • Can you confirm the server can communicate with the collector - telnet on port 443 for example
  • Run wireshark on the server to check for tcp/443 traffic to the collector
  • Confirm that auditing is configured on the server (As per my previous example screenshot.

I hope it helps

Thanks

 

Take a backup before making any changes
Richie_C

Just to clarify. You need to hit the apply button, each time you make a change to the template. This is why I mentioned it, as its easy to forget. 

Take a backup before making any changes
gwaihir
New Contributor III

Hi @Richie_C sorry for late reply. I'm been a little busy.

 

The collector is on the same subnet that DC-Server so no firewall policy because there is not intra-vlan traffic or ACL policies.

 

From server to super there is a policy that allow: (all ports)

From Super to server: (all ports)

(I opened all ports just for trying)

 

Tcpdump from collector on server show 443 traffic

 

Policy audit already enabled.

 

I'm going to try disable AV and EDR software (as this is running on server, *no logs related to siem agent) 

 

Thank you!

gwaihir
New Contributor III

I updated the agent to 7.1.1 version and it solved everything.

 

Thank you!

dmontgomery
New Contributor III

In your credential settings what protocol are you using - WMI or OMI? I had to change mine to OMI.

gwaihir
New Contributor III

SNMP v3 for pam monitoring. For logs I'm trying to use the agent.

 

 

Labels
Top Kudoed Authors