How is a subparttern for a rule defined?
Rule Subpattern Definition: In FortiSIEM, a subpattern within a rule is used to define specific conditions and criteria that must be met for the rule to trigger an incident or alert.
Components of a Subpattern: The subpattern includes the following elements:
Filters: Criteria to filter the events that the rule will evaluate.
Aggregation: Conditions that define how events should be aggregated or grouped for analysis.
Time Window Definitions: Specifies the time frame over which the events will be evaluated to determine if the rule conditions are met.
Reference: Together, these components allow the system to efficiently and accurately detect patterns of interest within the event data.
References: FortiSIEM 6.3 User Guide, Rules and Patterns section, which explains the structure and configuration of rule subpatterns, including the use of filters, aggregation, and time window definitions.
Lonny
6 months agoNydia
6 months agoJanet
6 months agoMartha
6 months agoLeonardo
6 months agoHeidy
6 months agoAnisha
6 months agoMitsue
7 months agoStephane
7 months agoMargurite
5 months agoRebbecca
5 months agoHelaine
5 months agoJames
5 months agoNydia
7 months ago