A correlation rule is generating a high volume of detections. You have been asked to temporarily deactivate it so your team can investigate.
What will happen to previously generated detections while the rule is in a deactivated state?
You need to import a pre-built workflow into Fusion SOAR to automate a part of your incident response process.
Which file format would you use?
You find a Falcon Log Collector instance on a Linux system that is not connected to Fleet Management.
What command would you use to enroll the Falcon Log Collector?
Which CQL function should you use to count events by hostname?
Which are valid parse functions in CQL?
Which sequence correctly describes the process for duplicating a workflow in Fusion SOAR?
Which default parser would you use to parse the log event below?
Jan 15 14:22:07 host1 sshd[1234]: Failed login
Which two tags are compliant with the CrowdStrike Parsing Standard (CPS)?
Which three System alerts are enabled by default in Next-Gen SIEM for third-party connectors?
You are creating a correlation rule in Next-Gen SIEM to trigger alerts based on when the event occurred, regardless of when the event was ingested.
Which event timestamp should you select?