An administrator wants to search for events received from Linux and Windows agents.
Which attribute should the administrator use in search filters, to view events received from agents only.
Search Filters in FortiSIEM: When searching for specific events, administrators can use various attributes to filter the results.
Attribute for Agent Events: To view events received specifically from Linux and Windows agents, the attribute External Event Receive Agents should be used.
Function: This attribute filters events that are received from agents, distinguishing them from events received through other protocols or sources.
Search Efficiency: Using this attribute helps the administrator focus on events collected by FortiSIEM agents, making the search results more relevant and targeted.
Reference: FortiSIEM 6.3 User Guide, Event Search and Filters section, which describes the available attributes and their usage for filtering search results.
Tracie
21 days agoMinna
22 days agoLamonica
23 days agoTiffiny
12 days agoChara
14 days agoChandra
23 days agoAdria
1 months agoMalcom
1 months agoLavonna
10 days agoKate
23 days agoBillye
28 days agoStephaine
1 months agoDick
22 days agoVannessa
1 months agoIdella
1 months ago