If an incident’s status is Cleared, what does this mean?
Which two FortiSIEM components work together to provide real-time event correlation?
What does the Frequency field determine on a rule?
In the advanced analytical rules engine in FortiSIEM, multiple subpatterms can be referenced using which three operation?(Choose three.)
Refer to the exhibit.
A FortiSIEM administrator wants to group some attributes for a report, but is not able to do so successfully.
As shown in the exhibit, why are some of the fields highlighted in red?
Refer to the exhibit.
Which section contains the subpattren configuration settings that determine how many matching events are needed to trigger the rule?
Refer to the exhibit.
Which section contains the sortings that determine how many incidents are created?
In the CMDB page for a network device, the Configuration tab is unexpectedly empty. Which is a possible reason?
Which statement about global thresholds and per device thresholds is true?
Refer to the exhibits.
Three events are collected over a 10-minute time period from two servers: Server A and Server B.
Based on the settings tor the rule subpattern. how many incidents will the servers generate?