How does FortiSIEM update the incident table if a performance rule triggers repeatedly?
When a performance rule triggers repeatedly, FortiSIEM updates the existing incident by incrementing the Incident Count and refreshing the Last Seen timestamp. This avoids flooding the incident table with duplicates while still tracking repeated occurrences.
Lashandra
2 months agoHaydee
2 months agoGlenna
2 months agoTegan
3 months agoGlory
3 months agoStevie
3 months agoPaola
3 months agoCory
4 months agoVivienne
4 months agoGeorgeanna
4 months agoJolanda
4 months agoBette
4 months agoKati
4 months agoJillian
5 months ago