Fortinet black logo

Native Windows as UEBA Telemetry

Native Windows as UEBA Telemetry

Where an agent cannot be deployed, there are still events that can be collected from the Windows device using an agentless method such as OMI. However, about 50% of the UEBA ML model will miss necessary data.

A comparison can be found here:

Example UEBA events

UEBA ML models and required event sources

Installing and configuring the FortiSIEM Windows Agent is available here and agentless monitoring of Windows is described in the External Systems Configuration Guide (ESCG).

Native Windows as UEBA Telemetry

Where an agent cannot be deployed, there are still events that can be collected from the Windows device using an agentless method such as OMI. However, about 50% of the UEBA ML model will miss necessary data.

A comparison can be found here:

Example UEBA events

UEBA ML models and required event sources

Installing and configuring the FortiSIEM Windows Agent is available here and agentless monitoring of Windows is described in the External Systems Configuration Guide (ESCG).