How is a subparttern for a rule defined?
Rule Subpattern Definition: In FortiSIEM, a subpattern within a rule is used to define specific conditions and criteria that must be met for the rule to trigger an incident or alert.
Components of a Subpattern: The subpattern includes the following elements:
Filters: Criteria to filter the events that the rule will evaluate.
Aggregation: Conditions that define how events should be aggregated or grouped for analysis.
Time Window Definitions: Specifies the time frame over which the events will be evaluated to determine if the rule conditions are met.
Reference: Together, these components allow the system to efficiently and accurately detect patterns of interest within the event data.
References: FortiSIEM 6.3 User Guide, Rules and Patterns section, which explains the structure and configuration of rule subpatterns, including the use of filters, aggregation, and time window definitions.
Lonny
4 months agoNydia
4 months agoJanet
4 months agoMartha
4 months agoLeonardo
3 months agoHeidy
3 months agoAnisha
4 months agoMitsue
4 months agoStephane
4 months agoMargurite
3 months agoRebbecca
3 months agoHelaine
3 months agoJames
3 months agoNydia
4 months ago