Fortinet FCP - FortiSIEM 7.2 Analyst FCP_FSM_AN-7.2 Question # 2 Topic 1 Discussion

Fortinet FCP - FortiSIEM 7.2 Analyst FCP_FSM_AN-7.2 Question # 2 Topic 1 Discussion

FCP_FSM_AN-7.2 Exam Topic 1 Question 2 Discussion:
Question #: 2
Topic #: 1

Refer to the exhibit.

FCP_FSM_AN-7.2 Question 2

A FortiSIEM device is receiving syslog events from a FortiGate firewall. The FortiSIEM analyst is trying to search the raw event logs for the last two hours that contain the keyword "udp". However, they are getting no results from the search, which they know should be available. Based on the filter shown in the exhibit, why are there no search results?


A.

The analyst selected AND in the Next column. This is the wrong Boolean operator.


B.

The Time Range value should be set to Real-Time.


C.

The keyword is case sensitive. Instead of typing udp in the Value field, the analyst should type UDP.


D.

The analyst selected = in the Operator column. That is the wrong operator.


Get Premium FCP_FSM_AN-7.2 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.