What does the Frequency field determine on a rule?
Rule Evaluation in FortiSIEM: Rules in FortiSIEM are evaluated periodically to check if the defined conditions or subpatterns are met.
Frequency Field: The Frequency field in a rule determines the interval at which the rule's subpattern will be evaluated.
Evaluation Interval: This defines how often the system will check the incoming events against the rule's subpattern to determine if an incident should be triggered.
Impact on Performance: Setting an appropriate frequency is crucial to balance between timely detection of incidents and system performance.
Examples:
If the Frequency is set to 5 minutes, the rule will evaluate the subpattern every 5 minutes.
This means that every 5 minutes, the system will check if the conditions defined in the subpattern are met by the incoming events.
Reference: FortiSIEM 6.3 User Guide, Rules and Incidents section, which explains the Frequency field and how it impacts the evaluation of subpatterns in rules.
Rebbecca
3 months agoRupert
3 months agoScarlet
2 months agoJaleesa
2 months agoTheron
2 months agoVi
3 months agoJulio
3 months agoHelene
2 months agoFrancisca
2 months agoUla
2 months agoYuki
3 months agoLucia
4 months agoLashandra
3 months agoArdella
3 months agoMona
3 months agoFrance
3 months agoJannette
4 months agoNguyet
4 months ago