An administrator wants to search for events received from Linux and Windows agents.
Which attribute should the administrator use in search filters, to view events received from agents only.
Search Filters in FortiSIEM: When searching for specific events, administrators can use various attributes to filter the results.
Attribute for Agent Events: To view events received specifically from Linux and Windows agents, the attribute External Event Receive Agents should be used.
Function: This attribute filters events that are received from agents, distinguishing them from events received through other protocols or sources.
Search Efficiency: Using this attribute helps the administrator focus on events collected by FortiSIEM agents, making the search results more relevant and targeted.
Reference: FortiSIEM 6.3 User Guide, Event Search and Filters section, which describes the available attributes and their usage for filtering search results.
Glory
2 months agoTiffiny
2 months agoReita
2 months agoAndra
1 months agoXochitl
2 months agoLavonda
2 months agoEstrella
2 months agoEladia
2 months agoLeonida
1 months agoLelia
1 months agoYvette
2 months agoCiara
2 months agoBuck
3 months agoAlex
3 months agoVirgie
2 months agoElouise
2 months agoJettie
3 months agoMarci
3 months agoRanee
3 months agoAntione
3 months ago