Fortinet FCP_FSM_AN-7.2 - FCP - FortiSIEM 7.2 Analyst
Refer to the exhibit.
According to the automation policy configuration shown in the exhibit, what happens if an associated rule triggers?
Refer to the exhibit.
What is the Group: FortiSIEM Analysts value referring to?
Which information can FortiSIEM retrieve from FortiClient EMS through an API connection?
Refer to the exhibit.
The analyst is troubleshooting the analytics query shown in the exhibit.
Why is this search not producing any results?
Refer to the exhibit.
If a rule containing the automation policy shown in the exhibit triggers, what will happen?
Which two settings must you configure to allow FortiSIEM to apply tags to devices in FortiClient EMS? (Choose two.)
Refer to the exhibit.
A FortiSIEM device is receiving syslog events from a FortiGate firewall. The FortiSIEM analyst is trying to search the raw event logs for the last two hours that contain the keyword "udp". However, they are getting no results from the search, which they know should be available. Based on the filter shown in the exhibit, why are there no search results?
Which items are used to define a subpattern?
Refer to the exhibit.
Which two lookup types can you reference as the subquery in a nested analytics query? (Choose two.)