Microsoft Internet Authentication Server (IAS)
What is Discovered and Monitored
Protocol | Information Discovered | Metrics Collected | Used For |
---|---|---|---|
WMI | |||
Syslog | |||
Windows Agent |
|
|
IAS logs |
Event Types
In ADMIN > Device Support > Event Types, search for "microsoft isa" to see the event types associated with this device.
Configuration
WMI
See WMI Configurations in the Microsoft Windows Server Configuration section.
Syslog
You must configure your Microsoft Internet Authentication Server to save logs, and then you can use the Windows Agent Manager to configure the type of log information you want sent to FortiSIEM.
- Log in to your server as an administrator.
- Go to Start > Administrative Tools > Internet Authentication Service.
- In the left-hand navigation, select Remote Access Logging, then select Local File.
- Right-click on Local File to open the Properties menu, and then select Log File.
- For Directory, enter
C:\WINDOWS\system32\LogFiles\IAS
. - Click OK.
You can now use Windows Agent Installation Guide to configure what information will be sent to FortiSIEM.