Fortinet white logo
Fortinet white logo

External Systems Configuration Guide

Microsoft SharePoint

Microsoft SharePoint

What is Discovered and Monitored

Protocol

Information discovered

Metrics/Logs collected

Used for

LOGbinder Agent

SharePoint logs - Audit trail integrity, Access control changes, Document updates, List updates, Container object updates, Object changes, Object Import/Exports, Document views, Information Management Policy changes

Log analysis and compliance

Event Types

In ADMIN > Device Support > Event, search for "sharepoint" in the Description column to see the event types associated with this device.

Reports

In RESOURCE > Reports , search for "sharepoint" in the Name column to see the reports associated with this application or device.

Configuration

Microsoft SharePoint logs are supported via LOGbinder SP agent from Monterey Technology group. The agent must be installed on the SharePoint server. Configure the agent to write logs to Windows Security log. FortiSIEM simply reads the logs from windows security logs via WMI and categorizes the SharePoint specific events and parses SharePoint specific attributes.

Installing and Configuring LOGbinder SP Agent

Microsoft SharePoint

Microsoft SharePoint

What is Discovered and Monitored

Protocol

Information discovered

Metrics/Logs collected

Used for

LOGbinder Agent

SharePoint logs - Audit trail integrity, Access control changes, Document updates, List updates, Container object updates, Object changes, Object Import/Exports, Document views, Information Management Policy changes

Log analysis and compliance

Event Types

In ADMIN > Device Support > Event, search for "sharepoint" in the Description column to see the event types associated with this device.

Reports

In RESOURCE > Reports , search for "sharepoint" in the Name column to see the reports associated with this application or device.

Configuration

Microsoft SharePoint logs are supported via LOGbinder SP agent from Monterey Technology group. The agent must be installed on the SharePoint server. Configure the agent to write logs to Windows Security log. FortiSIEM simply reads the logs from windows security logs via WMI and categorizes the SharePoint specific events and parses SharePoint specific attributes.

Installing and Configuring LOGbinder SP Agent