How does FortiSIEM update the incident table if a performance rule triggers repeatedly?
When a performance rule triggers repeatedly, FortiSIEM updates the existing incident by incrementing the Incident Count and refreshing the Last Seen timestamp. This avoids flooding the incident table with duplicates while still tracking repeated occurrences.
Vivienne
5 days agoGeorgeanna
11 days agoJolanda
16 days agoBette
21 days agoKati
26 days agoJillian
1 months ago