The correct answer is A. The FortiSIEM Study Guide explicitly lists Create Rule as one of the actions that can be performed directly from Analytics search results. The guide states that to perform actions on results, an analyst clicks Actions and can choose options such as Email Result, Export Result, Add Result to Case, Copy To New Tab, Save Report, and Create Rule. The rules lesson further explains what happens after clicking Create Rule: FortiSIEM opens a new rule configuration window and creates a subpattern based on the analytics search parameters. It states that FortiSIEM uses the analytics search filter conditions to create the rule subpattern filter conditions, uses the search display conditions to create the rule Group By conditions, and sets the Aggregate condition to COUNT(Matched Events) >= 1. Creating a new rule manually under Resources > Rules would work, but it is slower because the analyst must manually re-enter the search criteria. The direct Analytics > Actions > Create Rule workflow is the quickest method.
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit