Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Fortinet Exam NSE5_FSM-6.3 Topic 2 Question 19 Discussion

Actual exam question for Fortinet's NSE5_FSM-6.3 exam
Question #: 19
Topic #: 2
[All NSE5_FSM-6.3 Questions]

Refer to the exhibit.

A FortiSIEM is continuously receiving syslog events from a FortiGate firewall The FortiSlfcM administrator is trying to search the raw event logs for the last two hours that contain the keyword tcp . However, the administrator is getting no results from the search.

Based on the selected filters shown in the exhibit, why are there no search results?

Show Suggested Answer Hide Answer
Suggested Answer: D

Search Filters in FortiSIEM: When searching for specific events, administrators can use various attributes to filter the results.

Attribute for Agent Events: To view events received specifically from Linux and Windows agents, the attribute External Event Receive Agents should be used.

Function: This attribute filters events that are received from agents, distinguishing them from events received through other protocols or sources.

Search Efficiency: Using this attribute helps the administrator focus on events collected by FortiSIEM agents, making the search results more relevant and targeted.

Reference: FortiSIEM 6.3 User Guide, Event Search and Filters section, which describes the available attributes and their usage for filtering search results.


Contribute your Thoughts:

Jina
1 months ago
The administrator must have been channeling their inner Sherlock Holmes, trying to solve the case of the missing search results. Maybe they should have tried the elementary technique of checking their work.
upvoted 0 times
Dominic
15 days ago
In the Time section, they should select 24 hours instead of 2 hours.
upvoted 0 times
...
Vallie
16 days ago
The keyword is case sensitive. They should type tcp instead of TCP.
upvoted 0 times
...
...
Nathalie
1 months ago
Selecting 'AND' in the Next drop-down list? That's like trying to bake a cake with a wrench. Talk about using the wrong tool for the job!
upvoted 0 times
Thurman
9 days ago
User2: Agreed, it's like using a wrench to bake a cake.
upvoted 0 times
...
Aja
22 days ago
User1: Yeah, selecting 'AND' was definitely not the right move.
upvoted 0 times
...
...
Chandra
1 months ago
The wrong operator in the Operator column? That's like trying to catch a fish with a hammer. I hope the administrator didn't drop the ball on this one.
upvoted 0 times
...
Leonora
1 months ago
Ah, the classic time period blunder. The administrator should have selected 'Last 24 hours' instead of 'Relative Last 2 hours'. Time flies when you're not watching the clock!
upvoted 0 times
...
Ruth
2 months ago
Hmm, that makes sense. Maybe we should double check the filters and make the necessary adjustments.
upvoted 0 times
...
Kattie
2 months ago
I disagree, I believe the issue is with the time period selected. It should be 24 hours instead of 2.
upvoted 0 times
...
Ruth
2 months ago
I think the reason there are no search results is because the keyword is case sensitive.
upvoted 0 times
...
Audrie
2 months ago
The keyword is case-sensitive, so the administrator should type 'tcp' instead of 'TCP'. Rookie mistake!
upvoted 0 times
Pedro
26 days ago
User4: And they also selected the wrong boolean operator. It should be OR instead of AND.
upvoted 0 times
...
Renay
1 months ago
User3: In the Time section, they selected the wrong time period. It should be 24 hours.
upvoted 0 times
...
Shawnda
1 months ago
User2: Yeah, that's a common mistake. It needs to be lowercase.
upvoted 0 times
...
Myra
1 months ago
User1: The keyword is case sensitive. They should type 'tcp' instead of 'TCP.
upvoted 0 times
...
...

Save Cancel