QuestionQ29
Detection CapabilitiesRefer to the exhibit.

You are examining the Triggering Events page for a FortiSIEM incident. Because the topology contains only one firewall, you want to remove the Reporting IP column.
How can you do this?
- A Customize the display columns for this incident.
- B Remove the Reporting IP attribute from the raw logs using parsing rules.
- C Disable correlation for the Reporting IP field in the rule subpattern.
- D Clear the Reporting IP field from the Triggered Attributes section when you configure the Incident Action.
Community Discussion