QuestionQ5
Detection CapabilitiesYou are setting up a new FortiSIEM rule to trigger incidents after receiving a specified number of either Fortigate-Traffic-Violation or Fortigate-Traffic-Denied event types. Although a single subpattern could accomplish this, you choose to create two separate subpatterns—one for each event type—and correlate them with the OR operator.
Which two benefits does this method provide?
Choose two
- A Each subpattern can use a different group by condition.
- B Each subpattern can use a different time window condition.
- C Each subpattern can use a different aggregate condition.
- D Each subpattern can trigger its own notification policy.
Community Discussion