How can you query the configuration management database (CMDB) in an analytics search?
The correct answer is A because CMDB objects are referenced from the Value field after selecting the appropriate event attribute and operator. The FortiSIEM Study Guide gives a structured search example that references the CMDB. In that example, the attribute is Reporting IP, the operator is IN, and the value is selected from CMDB groups such as Devices: Windows and Networks: Inside Net. The guide explains that to show events reported by Windows servers within a specific network, you set the attribute and operator first, then browse the CMDB and select the relevant CMDB group value. This confirms the workflow: the CMDB reference is chosen as the value of the condition, not as the attribute itself. Option B is incorrect because the CMDB tab is not used to launch the analytics search this way. Option C is not a valid workflow. Option D is wrong because the attribute is selected from event or CMDB attribute lists, while the CMDB object or group is selected in the value field.
Elizabeth
3 days agoVirgina
8 days agoPaola
13 days agoHollis
19 days agoElvera
24 days agoVirgina
29 days agoLauran
1 month agoCraig
1 month agoAshton
1 month ago