Microsoft SharePoint
What is Discovered and Monitored
Protocol |
Information discovered |
Metrics/Logs collected |
Used for |
---|---|---|---|
LOGbinder Agent |
SharePoint logs - Audit trail integrity, Access control changes, Document updates, List updates, Container object updates, Object changes, Object Import/Exports, Document views, Information Management Policy changes |
Log analysis and compliance |
Event Types
In ADMIN > Device Support > Event, search for "sharepoint" in the Description column to see the event types associated with this device.
Reports
In RESOURCE > Reports , search for "sharepoint" in the Name column to see the reports associated with this application or device.
Configuration
Microsoft SharePoint logs are supported via LOGbinder SP agent from Monterey Technology group. The agent must be installed on the SharePoint server. Configure the agent to write logs to Windows Security log. FortiSIEM simply reads the logs from windows security logs via WMI and categorizes the SharePoint specific events and parses SharePoint specific attributes.
Installing and Configuring LOGbinder SP Agent
- LOGbinder Install web link
- LOGbinder Configuration web link - remember to configure LOGbinder SP agent to write to Windows security log
- LOGbinder SP getting started document - remember to configure LOGbinder SP agent to write to Windows security log