How is a subparttern for a rule defined?
Rule Subpattern Definition: In FortiSIEM, a subpattern within a rule is used to define specific conditions and criteria that must be met for the rule to trigger an incident or alert.
Components of a Subpattern: The subpattern includes the following elements:
Filters: Criteria to filter the events that the rule will evaluate.
Aggregation: Conditions that define how events should be aggregated or grouped for analysis.
Time Window Definitions: Specifies the time frame over which the events will be evaluated to determine if the rule conditions are met.
Reference: Together, these components allow the system to efficiently and accurately detect patterns of interest within the event data.
References: FortiSIEM 6.3 User Guide, Rules and Patterns section, which explains the structure and configuration of rule subpatterns, including the use of filters, aggregation, and time window definitions.
Lonny
10 months agoNydia
11 months agoJanet
11 months agoMartha
11 months agoLeonardo
10 months agoHeidy
10 months agoAnisha
11 months agoMitsue
11 months agoStephane
11 months agoMargurite
10 months agoRebbecca
10 months agoHelaine
10 months agoJames
10 months agoNydia
11 months ago