Where must you configure rule notifications and automated remediation on FortiSIEM?
Advanced Analytical Rules Engine: FortiSIEM's rules engine allows for complex event correlation using multiple subpatterns.
Operations for Referencing Subpatterns:
FOLLOWED_BY: This operation is used to indicate that one event follows another within a specified time window.
OR: This logical operation allows for the inclusion of multiple subpatterns, where the rule triggers if any of the subpatterns match.
AND: This logical operation requires all referenced subpatterns to match for the rule to trigger.
Usage: These operations allow for detailed and precise event correlation, helping to detect complex patterns and incidents.
Reference: FortiSIEM 6.3 User Guide, Advanced Analytics Rules Engine section, which explains the use of different operations to reference subpatterns in rules.
Jessenia
2 months agoChau
1 months agoDortha
1 months agoHildegarde
1 months agoTarra
2 months agoDortha
17 days agoArthur
21 days agoMicaela
1 months agoLashawn
3 months agoCecil
2 months agoAleisha
2 months agoKenneth
3 months agoYen
3 months agoShenika
1 months agoPansy
1 months agoRhea
2 months agoJani
2 months agoGarry
3 months agoStephaine
3 months agoDorethea
3 months ago