How can you query the configuration management database (CMDB) in an analytics search?
The correct answer is A because CMDB objects are referenced from the Value field after selecting the appropriate event attribute and operator. The FortiSIEM Study Guide gives a structured search example that references the CMDB. In that example, the attribute is Reporting IP, the operator is IN, and the value is selected from CMDB groups such as Devices: Windows and Networks: Inside Net. The guide explains that to show events reported by Windows servers within a specific network, you set the attribute and operator first, then browse the CMDB and select the relevant CMDB group value. This confirms the workflow: the CMDB reference is chosen as the value of the condition, not as the attribute itself. Option B is incorrect because the CMDB tab is not used to launch the analytics search this way. Option C is not a valid workflow. Option D is wrong because the attribute is selected from event or CMDB attribute lists, while the CMDB object or group is selected in the value field.
Currently there are no comments in this discussion, be the first to comment!