QuestionQ29

Detection Capabilities

Refer to the exhibit.

Question Image

You are examining the Triggering Events page for a FortiSIEM incident. Because the topology contains only one firewall, you want to remove the Reporting IP column.

How can you do this?

  • A Customize the display columns for this incident.
  • B Remove the Reporting IP attribute from the raw logs using parsing rules.
  • C Disable correlation for the Reporting IP field in the rule subpattern.
  • D Clear the Reporting IP field from the Triggered Attributes section when you configure the Incident Action.
Explanation

FortiSIEM lets users customize the displayed columns for an incident view, allowing the Reporting IP column to be hidden without changing the underlying logs or correlation rule. Fortinet documents changing incident display columns by selecting the desired columns to display.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!