In the rules engine, which condition instructs FortiSIEM to summarize and count the matching evaluated data?
An administrator defines SMTP as a critical process on a Linux server.
It the SMTP process is stopped. FortiSIEM will generate a critical event with which event type?
An administrator is configuring FortiSIEM to discover network devices and receive syslog from network devices. Which statement is correct?
Which three ports can be used to send Syslogs to FortiSIEM? (Choose three.)
Refer to the exhibit.
It events are grouped by Event Type and User attributes in FortiSIEM. how many results will be displayed?
Refer to the exhibit.
A FortiSIEM administrator wants to group some attributes for a report, but is not able to do so successfully.
As shown in the exhibit, why are some of the fields highlighted in red?
Refer to the exhibit.
The output shows that the license is in which condition?
An administrator is using SNMP credential only for discovery of a Windows device. How will FortiSIEM handle this?
What does the Frequency field determine on a rule?