Osquery
Note: FortiSIEM 7.1.0 and Windows Agent 5.1 or later is required to utilize this feature.
osquery is an open-source simple instrumentation tool that can be used across the following operating systems, Windows, OS X (macOS), and Linux. It provides a simplified interface to query information held within an operating system itself, using an SQL based language.
In FortiSIEM, the user can create high level queries that will be pushed to Windows Agent, which will schedule, run and return data from the queries.
For more information on osquery, see osquery.
For more information on osquery schema, see osquery Schema.
Note: Don't forget to select Windows from the "Show only Tables compatible with" drop-down list when reviewing the osquery schema page to see the applicable schema.
FortiSIEM includes over 25 default system defined osquery templates, which you can see in Resources > Osquery, under Agent.