QuestionQ5

Detection Capabilities

You are setting up a new FortiSIEM rule to trigger incidents after receiving a specified number of either Fortigate-Traffic-Violation or Fortigate-Traffic-Denied event types. Although a single subpattern could accomplish this, you choose to create two separate subpatterns—one for each event type—and correlate them with the OR operator.

Which two benefits does this method provide?

Choose two
  • A Each subpattern can use a different group by condition.
  • B Each subpattern can use a different time window condition.
  • C Each subpattern can use a different aggregate condition.
  • D Each subpattern can trigger its own notification policy.
Explanation

Each FortiSIEM subpattern is independently defined with its own group-by attributes and aggregate conditions (thresholds). Using OR makes the rule trigger when either subpattern meets its own criteria, allowing the two event types to be grouped and thresholded differently. Notification policies and the rule time window are rule-level settings rather than separate per-subpattern benefits.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!