Device discovery information is stored in which database?
Which two FortiSIEM components work together to provide real-time event correlation?
Refer to the exhibit.
What do the yellow stars listed in the Monitor column indicate?
In the rules engine, which condition instructs FortiSIEM to summarize and count the matching evaluated data?
How is a subparttern for a rule defined?
What does the Frequency field determine on a rule?
An administrator is configuring FortiSIEM to discover network devices and receive syslog from network devices. Which statement is correct?
Which discovery scan type is prone to miss a device, if the device is quiet and the entry foe that device is not present in the ARP table of adjacent devices?
IF the reported packet loss is between 50% and 98%. which status is assigned to the device in the Availability column of summary dashboard?
An administrator defines SMTP as a critical process on a Linux server.
It the SMTP process is stopped. FortiSIEM will generate a critical event with which event type?
An administrator is in the process of renewing a FortiSIEM license. Which two commands will provide the system ID? (Choose two.)
Refer to the exhibit.
A FortiSIEM administrator wants to collect both SIEM event logs and performance and availability metrics (PAM) events from a Microsoft Windows server
Which protocol should the administrator select in the Access Protocol drop-down list so that FortiSIEM will collect both SIEM and PAM events?
Where do you configure rule notifications and automated remediation on FortiSIEM?
In the advanced analytical rules engine in FortiSIEM, multiple subpatterms can be referenced using which three operation?(Choose three.)
When configuring collectors located in geographically separated sites, what ports must be open on a front end firewall?